LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 14, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 28, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-32201 to its Known Exploited Vulnerabilities catalog on Apr 14, 2026, with a federal patch deadline of Apr 28, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Microsoft SharePoint Server contains an improper input validation vulnerability that permits an unauthorized attacker to perform spoofing over a network. The issue is tracked as CVE-2026-32201 and is classified under CWE-20.

How it works

The flaw belongs to the CWE-20 class of improper input validation weaknesses. In this product class an attacker supplies crafted data that the server does not correctly sanitize or verify before processing.

Am I affected? How to find it in your systems

Microsoft SharePoint Server deployments are the affected product. Inventory all on-premises SharePoint Server installations and any configurations that accept unauthenticated or lightly validated network input.

How to remediate

Apply mitigations per the vendor instructions provided in the official advisory. For any SharePoint components delivered through cloud services, follow applicable BOD 22-01 guidance.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure by limiting network access to SharePoint Server instances and monitoring for anomalous identity assertions.

If your data may have been exposed

Actively exploited vulnerabilities of this type can result in unauthorized access that leads to data exposure. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint Server
WeaknessCWE-20
Added to CISA KEVApr 14, 2026
Federal patch deadlineApr 28, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities