PT-2026-32853 · Microsoft · Sharepoint Server
Published
2026-04-14
·
Updated
2026-05-09
·
CVE-2026-32201
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server (affected versions not specified)
Microsoft SharePoint Server Subscription Edition (affected versions not specified)
Microsoft SharePoint Enterprise Server (affected versions not specified)
Description
Improper input validation in Microsoft SharePoint allows an unauthenticated remote attacker to perform spoofing over a network. This issue enables attackers to read and tamper with sensitive information, such as internal documents, records, and personal HR data, without requiring a password or user interaction. Exploitation can allow attackers to manipulate what users see, facilitating phishing, data manipulation, and social engineering at scale. Over 1,300 servers have been identified as remaining unpatched while the flaw is being actively exploited in real-world incidents.
Recommendations
Apply the security updates released on April 14.
Fix
LPE
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharepoint Server