cbcvebase.
CVE-2026-32201
published 2026-04-14

CVE-2026-32201: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

PriorityP181medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2026-04-28
Exploited in the wild
EPSS
21.48%
97.3th percentile
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5548.100316.0.5548.1003
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10417.2011416.0.10417.20114
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.19725.2021016.0.19725.20210
microsoftsharepoint_server< 16.0.19725.2021016.0.19725.20210
microsoftsharepoint_server
microsoftsharepoint_server

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-32201 is being chained with CVE-2026-45659 and CVE-2026-56164 in active attacks against on-premises SharePoint Server; monitor for RCE, IIS machine key theft, and deserialization activity post-exploitation
  • CVE-2026-32201 can be leveraged for phishing, unauthorized data manipulation, and social engineering within SharePoint environments; monitor for falsified content presentation and unexpected data changes in SharePoint
  • Over 1,300 unpatched internet-exposed SharePoint servers remain vulnerable; use Shadowserver or similar internet scanning data to identify unpatched instances in your environment
  • ·CVE-2026-32201 affects all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016; cloud/online versions are not mentioned as affected
  • ·The vulnerability is a spoofing flaw (improper input validation) with CVSS 6.5; it impacts confidentiality and integrity but not availability
  • ·Microsoft has not publicly disclosed the specific exploitation method or attributed attacks to a specific threat actor

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.