CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Unpatched Microsoft SharePoint servers remain exposed to CVE-2026-32201 spoofing attacks

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Over 1,300 Microsoft SharePoint servers remain unpatched against CVE-2026-32201, a spoofing vulnerability exploited as a zero-day and still actively abused in attacks. The flaw impacts SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, enabling threat actors without privileges to perform network spoofing via improper input validation. Exploitation can compromise confidentiality and integrity but does not restrict resource access. The issue was patched in April 2026 Patch Tuesday, added to CISA’s Known Exploited Vulnerabilities Catalog, and mandated for patching by U.S. federal agencies within two weeks. Fewer than 200 systems have been updated since the patch release.

Timeline

  1. 22.04.2026 09:53 1 articles · 2h ago

    CVE-2026-32201 added to KEV Catalog with federal patching deadline amid ongoing exploitation

    CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities Catalog on April 15, 2026, following Microsoft’s April 2026 Patch Tuesday advisory. The U.S. cybersecurity agency mandated Federal Civilian Executive Branch agencies to patch affected SharePoint servers by April 28, 2026, per Binding Operational Directive 22-01. Shadowserver reported over 1,300 unpatched servers exposed online, highlighting the continued risk posed by this zero-day spoofing vulnerability despite available fixes.

    Show sources

Information Snippets