Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-32201

Published 2026-04-14
Updated 3 months ago
Vendor/s
Microsoft
Product/s
SharePoint Server
Version/s
* > 16.0.19725.20210
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
6.5
/ 10
Medium
Severity Details
Base score
6.5 Medium
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Description

CVE-2026-32201 is a medium-severity spoofing vulnerability in Microsoft SharePoint Server that is actively exploited. Patch affected versions immediately.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
sharepoint_server * 16.0.19725.20210 vulnerable
sharepoint_server 2016 2016 vulnerable
sharepoint_server 2019 2019 vulnerable

Related weakness (CWE)

CWE-20

Remediation plan

1

Apply official patches

Download and install the latest security updates provided by Microsoft specifically for SharePoint Server to address the input validation flaw.

2

Update affected systems

Ensure SharePoint Server 2016, 2019, and Subscription Edition instances are updated to versions beyond 16.0.19725.20210 to mitigate the vulnerability.

3

Restrict access

Implement network-level access controls and Web Application Firewalls (WAF) to limit exposure of SharePoint interfaces to trusted internal networks only.

4

Monitor for exploitation

Review SharePoint ULS logs and IIS logs for unusual requests or malformed input patterns that indicate attempted spoofing or bypass attempts.

Detection Guidance

"Organizations should monitor IIS and SharePoint Unified Logging Service (ULS) logs for anomalous HTTP requests targeting SharePoint endpoints. Look for unexpected input patterns in headers or parameters that deviate from standard user behavior. Since this is a network-based spoofing vulnerability, security teams should also deploy network intrusion detection system (NIDS) signatures designed to identify malformed packets or unauthorized redirection attempts targeting SharePoint server ports."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management