Microsoft SharePoint Server spoofing vulnerability (actively exploited) (CVE-2026-32201)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft patched CVE-2026-32201 in Microsoft SharePoint Server, a spoofing vulnerability that was exploited in attacks and could affect confidentiality and integrity over the network. The flaw stems from improper input validation and lets an unauthorized attacker spoof activity over a network. Microsoft has not said how the abuse was carried out or who was behind it, which makes the patch a priority for exposed SharePoint deployments.
Related Happenings
Rising critical Microsoft vulnerabilities across Windows, Azure, Dynamics 365, and Office
Target Trend
First: 19.05.2026 17:00
Last: 19.05.2026 17:00
Sources 1
About this happening:
Microsoft’s vulnerability volume stayed broadly stable, but **critical flaws** doubled year over year across **Windows, Azure, Dynamics 365, and Office**, increasing the likelihoo...
Rising critical Microsoft vulnerabilities across Windows, Azure, Dynamics 365, and Office
Target TrendAbout this happening: Microsoft’s vulnerability volume stayed broadly stable, but **critical flaws** doubled year over year across **Windows, Azure, Dynamics 365, and Office**, increasing the likelihoo...
Windows cldflt.sys privilege escalation (CVE-2020-17103)
Vulnerability
First: 18.05.2026 01:30
Last: 18.05.2026 01:30
Sources 1
About this happening:
A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...
Windows cldflt.sys privilege escalation (CVE-2020-17103)
VulnerabilityAbout this happening: A public **MiniPlasma** proof-of-concept has renewed concern around the **Windows cldflt.sys Cloud Filter driver** because it can elevate a **standard user** to **SYSTEM** on **fu...
Azure Backup for AKS privilege escalation flaw
Vulnerability
First: 16.05.2026 23:55
Last: 16.05.2026 23:55
Sources 1
About this happening:
A **critical Azure Backup for AKS** privilege-escalation flaw was independently validated, exposing Kubernetes clusters to **cluster-admin** takeover from the low-privileged **Bac...
Azure Backup for AKS privilege escalation flaw
VulnerabilityAbout this happening: A **critical Azure Backup for AKS** privilege-escalation flaw was independently validated, exposing Kubernetes clusters to **cluster-admin** takeover from the low-privileged **Bac...
Windows 11 BitLocker bypass YellowKey security flaw
Vulnerability
First: 14.05.2026 10:27
Last: 14.05.2026 10:27
Sources 1
About this happening:
**YellowKey** is a **Windows BitLocker security feature bypass** tracked as **CVE-2026-45585** that can expose **BitLocker-protected drives** through the **Windows Recovery Enviro...
Windows 11 BitLocker bypass YellowKey security flaw
VulnerabilityAbout this happening: **YellowKey** is a **Windows BitLocker security feature bypass** tracked as **CVE-2026-45585** that can expose **BitLocker-protected drives** through the **Windows Recovery Enviro...
Latest development: 20.05.2026 10:31
Microsoft assigned CVE-2026-45585 to YellowKey, a Windows BitLocker security feature bypass, and recommended removing autofstx.exe from the Session Manager BootExecute REG_MULTI_SZ value, reestablishing BitLocker trust for WinRE, and moving already encrypted devices from TPM-only to TPM+PIN to require a pre-boot PIN.
Windows ikeext.dll double-free RCE (CVE-2026-33824)
Vulnerability
First: 13.05.2026 16:46
Last: 13.05.2026 16:46
Sources 1
About this happening:
**CVE-2026-33824** is a **double-free flaw** in **Windows ikeext.dll** that can let an **unauthenticated attacker** trigger **remote code execution** on systems with **IKEv2** ena...
Windows ikeext.dll double-free RCE (CVE-2026-33824)
VulnerabilityAbout this happening: **CVE-2026-33824** is a **double-free flaw** in **Windows ikeext.dll** that can let an **unauthenticated attacker** trigger **remote code execution** on systems with **IKEv2** ena...
Timeline
-
14.04.2026 20:41 2 articles · 1mo ago
Microsoft patches actively exploited SharePoint Server spoofing flaw
Mitigation Patch UpdateMicrosoft patched CVE-2026-32201 in Microsoft SharePoint Server, a spoofing vulnerability caused by improper input validation that was exploited in attacks. An unauthorized attacker could spoof activity over a network and potentially view sensitive information or alter disclosed information, while Microsoft did not disclose how the flaw was exploited or who disclosed it.
Show sources
- Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days — www.bleepingcomputer.com — 14.04.2026 20:41
- Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks — www.bleepingcomputer.com — 22.04.2026 09:53