CVE-2026-32201 is a medium-severity spoofing vulnerability in Microsoft SharePoint Server that is actively exploited. Patch affected versions immediately.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| sharepoint_server | * | 16.0.19725.20210 | vulnerable |
| sharepoint_server | 2016 | 2016 | vulnerable |
| sharepoint_server | 2019 | 2019 | vulnerable |
Download and install the latest security updates provided by Microsoft specifically for SharePoint Server to address the input validation flaw.
Ensure SharePoint Server 2016, 2019, and Subscription Edition instances are updated to versions beyond 16.0.19725.20210 to mitigate the vulnerability.
Implement network-level access controls and Web Application Firewalls (WAF) to limit exposure of SharePoint interfaces to trusted internal networks only.
Review SharePoint ULS logs and IIS logs for unusual requests or malformed input patterns that indicate attempted spoofing or bypass attempts.
"Organizations should monitor IIS and SharePoint Unified Logging Service (ULS) logs for anomalous HTTP requests targeting SharePoint endpoints. Look for unexpected input patterns in headers or parameters that deviate from standard user behavior. Since this is a network-based spoofing vulnerability, security teams should also deploy network intrusion detection system (NIDS) signatures designed to identify malformed packets or unauthorized redirection attempts targeting SharePoint server ports."
Experience superior visibility and a simpler approach to cyber risk management