PT-2026-32853 · Microsoft · Sharepoint Server

Published

2026-04-14

·

Updated

2026-05-09

·

CVE-2026-32201

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Server Subscription Edition (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified)
Description Improper input validation in Microsoft SharePoint allows an unauthenticated remote attacker to perform spoofing over a network. This issue enables attackers to read and tamper with sensitive information, such as internal documents, records, and personal HR data, without requiring a password or user interaction. Exploitation can allow attackers to manipulate what users see, facilitating phishing, data manipulation, and social engineering at scale. Over 1,300 servers have been identified as remaining unpatched while the flaw is being actively exploited in real-world incidents.
Recommendations Apply the security updates released on April 14.

Fix

LPE

RCE

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-05272
CVE-2026-32201

Affected Products

Sharepoint Server