s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2026-32201

📛 CVE Title

Microsoft SharePoint Server Spoofing Vulnerability

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Overview

State
PUBLISHED
Assigner (CNA)
microsoft
CVSS severity
MEDIUM
CVSS score
CVSS 6.5 / 10 6.5 6.5 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C
Effective score
6.5 / 10 MEDIUM source: CNA overview
MSRC score
6.5 / 10 MEDIUM MS rating: Important · Spoofing
CWE(s)
CWE-20
Reserved
2026-03-11
Published
2026-04-14 07:00 UTC
Last updated
2026-04-14 07:00 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/32xxx/CVE-2026-32201.json

CISA Known Exploited Vulnerabilities CISA KEV

CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.

Vulnerability name
Microsoft SharePoint Server Improper Input Validation Vulnerability
Vendor / project
Microsoft
Product
SharePoint Server
Date added to KEV
2026-04-14
Remediation due
2026-04-28
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Ransomware campaign use
Unknown
CISA notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32201
CISA listing
www.cisa.gov/known-exploited-vulnerabilities-catalog

NVD triage scoring NVD CVE 2.0

Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.

NVD published
2026-04-14 18:17:27 UTC
NVD last modified
2026-04-14 19:37:08 UTC
NVD CVSS v3.1
CVSS 6.5 / 10 6.5 6.5 / 10 MEDIUM source: secure@microsoft.com
NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability subscore
3.9 / 10
Impact subscore
2.5 / 10
EPSS score
0.0944 (probability of exploitation in next 30 days)
EPSS percentile
92.91% vs all CVEs — higher = more likely to be exploited, as of 2026-05-25

NVD / KEV / EPSS data refreshed 2026-05-25 14:36 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-22587
Assigner
microsoft
Published
Apr 14, 2026, 4:58:36 PM
Updated
May 12, 2026, 5:39:35 PM
EUVD base score (CVSS 3.1)
6.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C
EUVD-reported EPSS
8.9200
Vendors
Microsoft
Products
Microsoft SharePoint Server Subscription Edition (16.0.0 <16.0.19725.20210)
Microsoft SharePoint Server 2019 (16.0.0 <16.0.10417.20114)
Microsoft SharePoint Enterprise Server 2016 (16.0.0 <16.0.5548.1003)

ENISA description: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

EUVD references (1)

Microsoft Security Response Center MSRC

Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-29 03:00 UTC (source: CVRF).

MS severity
Important
Impact
Spoofing
MS CVSS base score
6.5 / 10 (temporal 6.0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C
Exploit assessment
Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected
Release
2026-Apr
Microsoft remediations / KB articles (6)
Microsoft FAQ (1)

According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?

An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability).

Affected products (3)

VendorProductVersionsPlatforms
Microsoft Microsoft SharePoint Enterprise Server 2016 16.0.0 (affected) x64-based Systems
Microsoft Microsoft SharePoint Server 2019 16.0.0 (affected) x64-based Systems
Microsoft Microsoft SharePoint Server Subscription Edition 16.0.0 (affected) x64-based Systems

Affected products — CPE 2.3 (3) NVD

NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.

  • cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*
  • cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (11)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

NVD-tagged references (2)

Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.

Remediations (10)

  • web:app.opencve.io

    Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the Microsoft security update for CVE‑2026‑32201 as documented in the Microsoft Security Update Guide. Restart the SharePoint services or reboot the servers if required by the update.

    2026-05-23 20:05 UTC
  • web:carthageelectronics.com

    Status: Actively exploited — CISA KEV listed — patch by May 12, 2026 What Happened On April 28, 2026 , CISA added CVE - 2026 -32202 to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of May 12, 2026 . This vulnerability is the result of an incomplete patch Microsoft released in February for CVE - 2026 -21510.

    2026-05-23 20:05 UTC
  • web:dailysecurityreview.com

    The combination of CVE-2026-32201 and CVE - 2026 -32202 in active exploitation makes May's Patch Tuesday a priority cycle. Organizations running SharePoint Server on-premises and those with NTLM still active in their Active Directory environments face the most immediate risk.

    2026-05-23 20:05 UTC
  • web:nvd.nist.gov

    Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

    2026-05-23 20:05 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-23 20:05 UTC
  • web:securityboulevard.com

    Microsoft addresses 163 CVEs in the April 2026 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild. Microsoft patched 163 CVEs in its April 2026 Patch Tuesday release, with eight rated critical, 154 rated as important and one rated as moderate.

    2026-05-23 20:05 UTC
  • web:undercodetesting.com

    What Undercode Say: Key Takeaway 1: CVE-2026-32201 is a high-risk, actively exploited zero-day requiring immediate patching. Key Takeaway 2: Detection and mitigation require a multi-layered approach, combining PowerShell commands, network monitoring, and log analysis.

    2026-05-23 20:05 UTC
  • web:www.indusface.com

    Without detailed logging, early stages of exploitation can go unnoticed. CVE-2026-32201 : Mitigation & Remediation Organizations should apply Microsoft's April 2026 security updates for affected SharePoint versions as the primary remediation step. Internet-facing SharePoint deployments should be prioritized due to increased exposure.

    2026-05-23 20:05 UTC
  • web:www.msn.com

    CISA mandates rapid SharePoint zero-day remediation On May 12, 2026 , CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities catalog, setting a May 26 remediation deadline for federal ...

    2026-05-23 20:05 UTC
  • web:www.sentinelone.com

    CVE-2026-32201 is an authentication bypass vulnerability in Microsoft SharePoint Server. Learn about its impact, affected versions, and mitigation methods.

    2026-05-23 20:05 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-32201.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-32201",
                "options": [
                  {
                    "Exploitation": "active"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-04-09T00:00:00+00:00",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          },
          {
            "other": {
              "content": {
                "dateAdded": "2026-04-14",
                "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201"
              },
              "type": "kev"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-04-16T03:55:16.734Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "references": [
          {
            "tags": [
              "government-resource"
            ],
            "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201"
          }
        ],
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SharePoint Enterprise Server 2016",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "16.0.5548.1003",
              "status": "affected",
              "version": "16.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SharePoint Server 2019",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "16.0.10417.20114",
              "status": "affected",
              "version": "16.0.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "platforms": [
            "x64-based Systems"
          ],
          "product": "Microsoft SharePoint Server Subscription Edition",
          "vendor": "Microsoft",
          "versions": [
            {
              "lessThan": "16.0.19725.20210",
              "status": "affected",
              "version": "16.0.0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*",
                  "versionEndExcluding": "16.0.5548.1003",
                  "versionStartIncluding": "16.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "16.0.10417.20114",
                  "versionStartIncluding": "16.0.0",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
                  "versionEndExcluding": "16.0.19725.20210",
                  "versionStartIncluding": "16.0.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2026-04-14T14:00:00.000Z",
      "descriptions": [
        {
          "lang": "en-US",
          "value": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-20",
              "description": "CWE-20: Improper Input Validation",
              "lang": "en-US",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-05-12T17:39:35.602Z",
        "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
        "shortName": "microsoft"
      },
      "references": [
        {
          "name": "Microsoft SharePoint Server Spoofing Vulnerability",
          "tags": [
            "vendor-advisory",
            "patch"
          ],
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201"
        }
      ],
      "title": "Microsoft SharePoint Server Spoofing Vulnerability"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
    "assignerShortName": "microsoft",
    "cveId": "CVE-2026-32201",
    "datePublished": "2026-04-14T16:58:36.981Z",
    "dateReserved": "2026-03-11T01:49:58.658Z",
    "dateUpdated": "2026-05-12T17:39:35.602Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}