⚠ Actively exploited
Added to CISA KEV on 2026-04-14. Federal agencies required to patch by 2026-04-28. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable..

CVE-2026-32201Improper Input Validation in Microsoft Sharepoint Enterprise Server 2016

Severity
6.5MEDIUMNVD
EPSS
0.8%
top 25.76%
CISA KEV
KEV
Added 2026-04-14
Due 2026-04-28
Exploit
No known exploits
Timeline
PublishedApr 14
KEV addedApr 14
KEV dueApr 28
CISA Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages4 packages

NVDmicrosoft/sharepoint_server< 16.0.19725.20210+2
CVEListV5microsoft/microsoft_sharepoint_server_201916.0.016.0.10417.20114
CVEListV5microsoft/microsoft_sharepoint_enterprise_server_201616.0.016.0.5548.1003
CVEListV5microsoft/microsoft_sharepoint_server_subscription_edition16.0.016.0.19725.20210

🔴Vulnerability Details

4
CVEList
Microsoft SharePoint Server Spoofing Vulnerability2026-04-14
VulDB
Microsoft SharePoint Server 2019/LTSC 2021/LTSC 2024 input validation2026-04-14
GHSA
GHSA-jmj9-qm9w-hrqj: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network2026-04-14
VulnCheck
Microsoft SharePoint Server Improper Input Validation Vulnerability2026

📋Vendor Advisories

1
CISA
Microsoft SharePoint Server Improper Input Validation Vulnerability2026-04-14

🕵️Threat Intelligence

1
Krebs
Patch Tuesday, April 2026 Edition2026-04-14