Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft SharePoint Server spoofing vulnerability (actively exploited) (CVE-2026-32201)

Vulnerability
First reported
Last updated
Happening score
H score 51
1 unique sources, 2 articles

Summary

Hide ▲

Microsoft patched CVE-2026-32201 in Microsoft SharePoint Server, a spoofing vulnerability that was exploited in attacks and could affect confidentiality and integrity over the network. The flaw stems from improper input validation and lets an unauthorized attacker spoof activity over a network. Microsoft has not said how the abuse was carried out or who was behind it, which makes the patch a priority for exposed SharePoint deployments.

Related Happenings

Rising critical Microsoft vulnerabilities across Windows, Azure, Dynamics 365, and Office

Target Trend
First: 19.05.2026 17:00 Last: 19.05.2026 17:00 Sources 1

About this happening: Microsoft’s vulnerability volume stayed broadly stable, but **critical flaws** doubled year over year across **Windows, Azure, Dynamics 365, and Office**, increasing the likelihoo...

Windows cldflt.sys privilege escalation (CVE-2020-17103)

Vulnerability
First: 18.05.2026 01:30 Last: 18.05.2026 01:30 Sources 1

About this happening: A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...

Azure Backup for AKS privilege escalation flaw

Vulnerability
First: 16.05.2026 23:55 Last: 16.05.2026 23:55 Sources 1

About this happening: A **critical Azure Backup for AKS** privilege-escalation flaw was independently validated, exposing Kubernetes clusters to **cluster-admin** takeover from the low-privileged **Bac...

Windows 11 BitLocker bypass YellowKey security flaw

Vulnerability
First: 14.05.2026 10:27 Last: 14.05.2026 10:27 Sources 1

About this happening: **YellowKey** is a **Windows BitLocker security feature bypass** tracked as **CVE-2026-45585** that can expose **BitLocker-protected drives** through the **Windows Recovery Enviro...

Latest development: 20.05.2026 10:31

Microsoft assigned CVE-2026-45585 to YellowKey, a Windows BitLocker security feature bypass, and recommended removing autofstx.exe from the Session Manager BootExecute REG_MULTI_SZ value, reestablishing BitLocker trust for WinRE, and moving already encrypted devices from TPM-only to TPM+PIN to require a pre-boot PIN.

Windows ikeext.dll double-free RCE (CVE-2026-33824)

Vulnerability
First: 13.05.2026 16:46 Last: 13.05.2026 16:46 Sources 1

About this happening: **CVE-2026-33824** is a **double-free flaw** in **Windows ikeext.dll** that can let an **unauthenticated attacker** trigger **remote code execution** on systems with **IKEv2** ena...

Timeline

  1. 14.04.2026 20:41 2 articles · 1mo ago

    Microsoft patches actively exploited SharePoint Server spoofing flaw

    Mitigation Patch Update

    Microsoft patched CVE-2026-32201 in Microsoft SharePoint Server, a spoofing vulnerability caused by improper input validation that was exploited in attacks. An unauthorized attacker could spoof activity over a network and potentially view sensitive information or alter disclosed information, while Microsoft did not disclose how the flaw was exploited or who disclosed it.

    Show sources