CVE-2026-32201
Microsoft SharePoint Server Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 April 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 43.38% probability · 99th percentile
- CISA KEV
- Listed 14 April 2026 · due 28 April 2026
- Weakness
- CWE-20
- Affected
- microsoft/sharepoint server
- Source
- secure@microsoft.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32201
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.