CVE-2026-32201

Published Apr 14, 2026

Last updated 2 months ago

Exploit knownCVSS medium 6.5
OT
Zero-day
Server
Network
web application
Cloud
IoT

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-32201 is an improper input validation vulnerability affecting Microsoft Office SharePoint Server. This flaw allows an unauthorized attacker to perform spoofing attacks over a network. The vulnerability stems from inadequate validation of user-supplied input within SharePoint Server's network-facing components. Exploitation of CVE-2026-32201 can occur remotely without requiring authentication or user interaction, and with low attack complexity. This allows malicious actors to conduct spoofing attacks, potentially impersonating legitimate users or resources within the SharePoint environment. The vulnerability has been actively exploited in the wild as a zero-day.

Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
2.5
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity
MEDIUM

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Improper Input Validation Vulnerability
Exploit added on
Apr 14, 2026
Exploit action due
Apr 28, 2026
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-20
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://t.co/SRRYYVs3Jv

    @endi24

    19 Jul 2026

    2542 Impressions

    5 Retweets

    23 Likes

    18 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/denoKmLMkf https://t.co/lvM94DeVpG

    @EAlexStark

    17 Jul 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities https://t.co/Qr0dCd19Nh https://t.co/wD4LUwwYHc

    @dansantanna

    17 Jul 2026

    32 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Four on-premises SharePoint Server CVEs are actively exploited: CVE-2026-32201 (CVSS 6.5), CVE-2026-45659 (CVSS 8.8), CVE-2026-56164 (CVSS 9.8), and CVE-2026-58644 (CVSS 9.8). #DFIR_Radar https://t.co/ln2QdK28Q8

    @DFIR_Radar

    17 Jul 2026

    190 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    2 Replies

    0 Quotes

  5. CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Exploitation Warnings for SharePoint Server Demand Immediate Action https://t.co/uVEGqZq5Sn #CVE2026 #SharePoint #CyberSecurity

    @cyber_newsroom

    16 Jul 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. These security flaws (tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affect all supported self-hosted SharePoint Server versions. https://t.co/q9ukzEgfYf

    @jbhall56

    15 Jul 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: SharePoint Server Active Exploi… "On July 14, 2026, CISA issued an urgent alert regarding active exploitation of…" 🔗 https://t.co/A0C48eSEX9 #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymonito

    @SecurityAr58409

    15 Jul 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CISA warns SharePoint vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 are exploited in the wild. Patch and harden servers now. #CISA #SharePoint #Microsoft #CVE #CyberSecurity https://t.co/SN49kOAPnL

    @Daily_CyberSec

    15 Jul 2026

    375 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. ⚡️ May "In the Trend of VM" (#27): Linux EoP (CVE-2026-31431), ActiveMQ RCE (CVE-2026-34197), SharePoint spoofing (CVE-2026-32201), Adobe Reader RCE (CVE-2026-34621) #TrendVulns #Linux #ActiveMQ #Microsoft #Adobe ➡️ https://t.co/4aiqSqJ6Ig https://t.co/w6uc5BlpwN

    @leonov_av

    25 May 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. SharePoint Spoofing Flaw (CVE-2026-32201) Now Exposed on 1,370 IPs Worldwide—CISA Adds to KEV. Microsoft SharePoint Spoofing Flaw Now Exposed on 1,370 IPs—CISA Adds CVE-2026-32201 to KEV

    @lyrie_ai

    24 May 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  11. Top 5 Trending CVEs: 1 - CVE-2026-20133 2 - CVE-2025-20333 3 - CVE-2026-32201 4 - CVE-2026-32210 5 - CVE-2026-25253 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    28 Apr 2026

    224 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Top 5 Trending CVEs: 1 - CVE-2023-33308 2 - CVE-2022-42475 3 - CVE-2026-32201 4 - CVE-2026-33827 5 - CVE-2024-3721 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    22 Apr 2026

    129 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations