CVE-2026-32201
📛 CVE Title
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- microsoft
- CVSS severity
- MEDIUM
- CVSS score
- 6.5 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C- Effective score
- 6.5 / 10 MEDIUM source: CNA overview
- MSRC score
- 6.5 / 10 MEDIUM MS rating: Important · Spoofing
- CWE(s)
-
CWE-20 - Reserved
- 2026-03-11
- Published
- 2026-04-14 07:00 UTC
- Last updated
- 2026-04-14 07:00 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/32xxx/CVE-2026-32201.json
CISA Known Exploited Vulnerabilities CISA KEV
CISA has confirmed in-the-wild exploitation of this CVE. Federal agencies must remediate by the due date below; private orgs should treat it as priority-1.
- Vulnerability name
- Microsoft SharePoint Server Improper Input Validation Vulnerability
- Vendor / project
- Microsoft
- Product
- SharePoint Server
- Date added to KEV
- 2026-04-14
- Remediation due
- 2026-04-28
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Ransomware campaign use
- Unknown
- CISA notes
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-32201 ; https://nvd.nist.gov/vuln/detail/CVE-2026-32201
- CISA listing
- www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-04-14 18:17:27 UTC
- NVD last modified
- 2026-04-14 19:37:08 UTC
- NVD CVSS v3.1
- 6.5 / 10 MEDIUM source: secure@microsoft.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 2.5 / 10
- EPSS score
- 0.0944 (probability of exploitation in next 30 days)
- EPSS percentile
- 92.91% vs all CVEs — higher = more likely to be exploited, as of 2026-05-25
NVD / KEV / EPSS data refreshed 2026-05-25 14:36 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-22587 - Assigner
- microsoft
- Published
- Apr 14, 2026, 4:58:36 PM
- Updated
- May 12, 2026, 5:39:35 PM
- EUVD base score (CVSS 3.1)
-
6.5 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C - EUVD-reported EPSS
- 8.9200
- Vendors
- Microsoft
- Products
-
Microsoft SharePoint Server Subscription Edition (16.0.0 <16.0.19725.20210)Microsoft SharePoint Server 2019 (16.0.0 <16.0.10417.20114)Microsoft SharePoint Enterprise Server 2016 (16.0.0 <16.0.5548.1003)
ENISA description: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
EUVD references (1)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-07-29 03:00 UTC (source: CVRF).
- MS severity
- Important
- Impact
- Spoofing
- MS CVSS base score
- 6.5 / 10 (temporal 6.0)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C - Exploit assessment
- Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected
- Release
- 2026-Apr
Microsoft remediations / KB articles (6)
- 5002861 — Vendor Fix / Security Update (fixed build 16.0.5548.1003)
- https://support.microsoft.com/help/5002861 — None Available / 5002861
- 5002854 — Vendor Fix / Security Update (fixed build 16.0.10417.20114)
- https://support.microsoft.com/help/5002854 — None Available / 5002854
- 5002853 — Vendor Fix / Security Update (fixed build 16.0.19725.20210)
- https://support.microsoft.com/help/5002853 — None Available / 5002853
Microsoft FAQ (1)
According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?
An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed information (Integrity), but cannot limit access to the resource (Availability).
Affected products (3)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 |
16.0.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft SharePoint Server 2019 |
16.0.0 (affected)
|
x64-based Systems |
| Microsoft | Microsoft SharePoint Server Subscription Edition |
16.0.0 (affected)
|
x64-based Systems |
Affected products — CPE 2.3 (3) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
- Microsoft SharePoint Server Spoofing Vulnerability vendor-advisorypatch
Web references (11)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- 5002853 msrc
- 5002854 msrc
- 5002861 msrc
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201 rapid7:msrc.microsoft.com
- https://support.microsoft.com/help/5002853 rapid7:support.microsoft.com
- http://cwe.mitre.org/data/definitions/20.html rapid7:cwe.mitre.org
- https://support.microsoft.com/help/5002861 rapid7:support.microsoft.com
- https://www.cve.org/CVERecord?id=CVE-2026-32201 rapid7:www.cve.org
- https://support.microsoft.com/help/5002854 rapid7:support.microsoft.com
- https://attackerkb.com/topics/CVE-2026-32201 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22587 rapid7:euvd.enisa.europa.eu
NVD-tagged references (2)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201 secure@microsoft.com Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201 134c704f-9b21-4f2e-91b3-4a467353bcc0 US Government Resource
Remediations (10)
-
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the Microsoft security update for CVE‑2026‑32201 as documented in the Microsoft Security Update Guide. Restart the SharePoint services or reboot the servers if required by the update.
2026-05-23 20:05 UTC -
web:carthageelectronics.com
Status: Actively exploited — CISA KEV listed — patch by May 12, 2026 What Happened On April 28, 2026 , CISA added CVE - 2026 -32202 to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation deadline of May 12, 2026 . This vulnerability is the result of an incomplete patch Microsoft released in February for CVE - 2026 -21510.
2026-05-23 20:05 UTC -
web:dailysecurityreview.com
The combination of CVE-2026-32201 and CVE - 2026 -32202 in active exploitation makes May's Patch Tuesday a priority cycle. Organizations running SharePoint Server on-premises and those with NTLM still active in their Active Directory environments face the most immediate risk.
2026-05-23 20:05 UTC -
web:nvd.nist.gov
Secure .gov websites use HTTPS A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
2026-05-23 20:05 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-23 20:05 UTC -
web:securityboulevard.com
Microsoft addresses 163 CVEs in the April 2026 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild. Microsoft patched 163 CVEs in its April 2026 Patch Tuesday release, with eight rated critical, 154 rated as important and one rated as moderate.
2026-05-23 20:05 UTC -
web:undercodetesting.com
What Undercode Say: Key Takeaway 1: CVE-2026-32201 is a high-risk, actively exploited zero-day requiring immediate patching. Key Takeaway 2: Detection and mitigation require a multi-layered approach, combining PowerShell commands, network monitoring, and log analysis.
2026-05-23 20:05 UTC -
web:www.indusface.com
Without detailed logging, early stages of exploitation can go unnoticed. CVE-2026-32201 : Mitigation & Remediation Organizations should apply Microsoft's April 2026 security updates for affected SharePoint versions as the primary remediation step. Internet-facing SharePoint deployments should be prioritized due to increased exposure.
2026-05-23 20:05 UTC -
web:www.msn.com
CISA mandates rapid SharePoint zero-day remediation On May 12, 2026 , CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities catalog, setting a May 26 remediation deadline for federal ...
2026-05-23 20:05 UTC -
web:www.sentinelone.com
CVE-2026-32201 is an authentication bypass vulnerability in Microsoft SharePoint Server. Learn about its impact, affected versions, and mitigation methods.
2026-05-23 20:05 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-32201.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-32201",
"options": [
{
"Exploitation": "active"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-04-09T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
},
{
"other": {
"content": {
"dateAdded": "2026-04-14",
"reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201"
},
"type": "kev"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-04-16T03:55:16.734Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"government-resource"
],
"url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-32201"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Enterprise Server 2016",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.5548.1003",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Server 2019",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.10417.20114",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft SharePoint Server Subscription Edition",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "16.0.19725.20210",
"status": "affected",
"version": "16.0.0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:*",
"versionEndExcluding": "16.0.5548.1003",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:*",
"versionEndExcluding": "16.0.10417.20114",
"versionStartIncluding": "16.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*",
"versionEndExcluding": "16.0.19725.20210",
"versionStartIncluding": "16.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-04-14T14:00:00.000Z",
"descriptions": [
{
"lang": "en-US",
"value": "Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:F/RL:O/RC:C",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-20",
"description": "CWE-20: Improper Input Validation",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T17:39:35.602Z",
"orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"shortName": "microsoft"
},
"references": [
{
"name": "Microsoft SharePoint Server Spoofing Vulnerability",
"tags": [
"vendor-advisory",
"patch"
],
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201"
}
],
"title": "Microsoft SharePoint Server Spoofing Vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8",
"assignerShortName": "microsoft",
"cveId": "CVE-2026-32201",
"datePublished": "2026-04-14T16:58:36.981Z",
"dateReserved": "2026-03-11T01:49:58.658Z",
"dateUpdated": "2026-05-12T17:39:35.602Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}