CVE-2026-32201Active Exploitation(microsoft / sharepoint_server)

CRITICALCVSS 6.5 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 51 mentions and remains active

Immediate actions

  • Patch microsoft sharepoint_server systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-28. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • Active exploitation appears in 158 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 217 mentions across 40 observed days

What's happening

  • Active exploitation reported across 158 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 120 signals
  • Technical details provided in 104 signals
  • General: 20 classified signals
  • Peaked 38d ago at 51 mentions (2026-04-15); latest day: 1
  • 217 total mentions across 40 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline217 mentions / 40d
013263851Mentions · 2026-04-14: 19Mentions · 2026-04-15: 51Mentions · 2026-04-16: 21Mentions · 2026-04-17: 12Mentions · 2026-04-18: 4Mentions · 2026-04-19: 9Mentions · 2026-04-20: 5Mentions · 2026-04-21: 6Mentions · 2026-04-22: 16Mentions · 2026-04-23: 7Mentions · 2026-04-24: 4Mentions · 2026-04-25: 1Mentions · 2026-04-26: 2Mentions · 2026-04-27: 4Mentions · 2026-04-28: 5Mentions · 2026-04-29: 1Mentions · 2026-04-30: 3Mentions · 2026-05-01: 3Mentions · 2026-05-05: 3Mentions · 2026-05-06: 2Mentions · 2026-05-07: 2Mentions · 2026-05-09: 6Mentions · 2026-05-12: 1Mentions · 2026-05-13: 2Mentions · 2026-05-18: 1Mentions · 2026-05-23: 1Mentions · 2026-05-24: 4Mentions · 2026-05-25: 1Mentions · 2026-05-26: 1Mentions · 2026-06-10: 1Mentions · 2026-07-15: 5Mentions · 2026-07-16: 1Mentions · 2026-07-17: 4Mentions · 2026-07-19: 1Mentions · 2026-07-20: 1Mentions · 2026-07-21: 3Mentions · 2026-07-26: 1Mentions · 2026-07-27: 1Mentions · 2026-08-05: 1Mentions · 2026-08-11: 1PoC Mentioned / Linked · 2026-04-15: 4PoC Mentioned / Linked · 2026-04-23: 1PoC Mentioned / Linked · 2026-04-26: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-07-16: 1Exploit Tool / Code · 2026-04-15: 4Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-26: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-26: 1Active Exploitation · 2026-04-14: 13Active Exploitation · 2026-04-15: 43Active Exploitation · 2026-04-16: 17Active Exploitation · 2026-04-17: 9Active Exploitation · 2026-04-18: 4Active Exploitation · 2026-04-19: 7Active Exploitation · 2026-04-20: 4Active Exploitation · 2026-04-21: 4Active Exploitation · 2026-04-22: 10Active Exploitation · 2026-04-23: 4Active Exploitation · 2026-04-24: 1Active Exploitation · 2026-04-25: 1Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-27: 2Active Exploitation · 2026-04-28: 2Active Exploitation · 2026-04-30: 2Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-06: 2Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-09: 6Active Exploitation · 2026-05-12: 1Active Exploitation · 2026-05-13: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-24: 3Active Exploitation · 2026-05-26: 1Active Exploitation · 2026-07-15: 5Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-17: 3Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-21: 3Active Exploitation · 2026-07-26: 1Active Exploitation · 2026-07-27: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-11: 1Patch / Workaround · 2026-04-14: 7Patch / Workaround · 2026-04-15: 29Patch / Workaround · 2026-04-16: 16Patch / Workaround · 2026-04-17: 10Patch / Workaround · 2026-04-18: 3Patch / Workaround · 2026-04-19: 8Patch / Workaround · 2026-04-20: 3Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-04-22: 4Patch / Workaround · 2026-04-23: 5Patch / Workaround · 2026-04-24: 2Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-27: 3Patch / Workaround · 2026-04-28: 3Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 2Patch / Workaround · 2026-05-01: 3Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-07-15: 3Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-26: 1Technical Details · 2026-04-14: 14Technical Details · 2026-04-15: 33Technical Details · 2026-04-16: 10Technical Details · 2026-04-17: 8Technical Details · 2026-04-19: 5Technical Details · 2026-04-20: 3Technical Details · 2026-04-21: 2Technical Details · 2026-04-22: 8Technical Details · 2026-04-23: 3Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-07-15: 2Technical Details · 2026-07-16: 1Technical Details · 2026-07-17: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-21: 2Technical Details · 2026-07-26: 104-1404-1804-2204-2604-3005-0705-1805-2607-1707-2608-11
Signal classification4 categories
Active Exploitation
13763.1%
Patch
4922.6%
General
209.2%
Disclosure
115.1%
Referenced assets125 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-1419
Active Exploitation12Disclosure4Patch3
2026-04-1551
Active Exploitation40Disclosure3General2Patch6
2026-04-1621
Active Exploitation10General1Patch10
2026-04-1712
Active Exploitation8General1Patch3
2026-04-184
Active Exploitation2Patch2
2026-04-199
Active Exploitation6Patch3
2026-04-205
Active Exploitation3General1Patch1
2026-04-216
Active Exploitation4General1Patch1
2026-04-2216
Active Exploitation8Disclosure1General5Patch2
2026-04-237
Active Exploitation4General1Patch2
2026-04-244
Active Exploitation1General2Patch1
2026-04-251
Patch1
2026-04-262
Active Exploitation1Patch1
2026-04-274
Active Exploitation1General1Patch2
2026-04-285
Active Exploitation2General1Patch2
2026-04-291
Disclosure1
2026-04-303
Active Exploitation2Patch1
2026-05-013
Patch3
2026-05-053
Active Exploitation1General1Patch1
2026-05-062
Active Exploitation2
2026-05-072
Active Exploitation1Patch1
2026-05-096
Active Exploitation6
2026-05-121
Active Exploitation1
2026-05-132
Active Exploitation1Patch1
2026-05-181
Active Exploitation1
2026-05-231
Patch1
2026-05-244
Active Exploitation3General1
2026-05-251
Disclosure1
2026-05-261
Patch1
2026-06-101
Disclosure1
2026-07-155
Active Exploitation5
2026-07-161
Active Exploitation1
2026-07-174
Active Exploitation3General1
2026-07-191
General1
2026-07-201
Active Exploitation1
2026-07-213
Active Exploitation3
2026-07-261
Active Exploitation1
2026-07-271
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-111
Active Exploitation1
Full discourse20 posts
  • Pirat_Nation 🔴@Pirat_Nation
    Patch

    Microsoft released a new patch to fix 167 security vulnerabilities across Windows and related software. Most importantly, two of them are zero-day vulnerabilities: >CVE-2026-32201: A SharePoint Server spoofing flaw already being actively exploited in the wild. >CVE-2026-33825: A flaw in Microsoft Defender that allows local attackers to gain SYSTEM-level access. They also fixed remote code execution issues in Microsoft Office. Guys If you use Windows, install these updates immediately especially if you run SharePoint or handle Office documents At this point just install Linux

    Post summary

    Microsoft has issued a patch for 167 vulnerabilities, including two zero‑day flaws that are already being exploited in the wild. Users are strongly advised to update Windows, especially if using SharePoint or Office.

    73157131.9K374130.8K
    332.5K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft Office remote code execution vulnerability CVE-2009-0238 & Microsoft SharePoint server improper input validation vulnerability CVE-2026-32201 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. https://t.co/U1Ff9SUWOz

    Post summary

    The tweet announces inclusion of two Microsoft CVEs in the DHS Known Exploited Vulnerabilities Catalog, indicating they are actively exploited, but no PoC, exploit code, patch, or debunking claim is provided.

    7314671716.9K
    299.0K followersView on X
  • Securízame@Securizame
    General

    Más de 1.300 servidores SharePoint expuestos a la vulnerabilidad CVE-2026-32201 de abril https://blog.segu-info.com.ar/2026/04/mas-de-1300-servidores-sharepoint.html #Internet #Noticia #Tecnología #CiberSeguridad vía @SeguInfo https://t.co/haAZEVxJde

    Post summary

    The tweet highlights that over 1,300 SharePoint servers are vulnerable to CVE-2026‑32201, but offers no further technical or remedial details.

    126051224.0K
    15.4K followersView on X
  • Thorsten E.@endi24
    General

    SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® https://www.tenable.com/blog/cve-2026-32201-cve-2026-45659-cve-2026-56164-faq-sharepoint-server-exploitation

    Post summary

    The text announces a Tenable FAQ blog post covering three SharePoint CVEs, but it does not provide any detailed exploit, patch, or technical information.

    05023182.8K
    4.7K followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    We are also scanning & reporting Microsoft SharePoint CVE-2026-32201 (Improper input validation in SharePoint allows an unauthorized attacker to perform spoofing over a network). This vulnerability is known exploited in the wild & on @CISACyber KEV. 1370 IPs seen unpatched. https://t.co/d2JmElo4rY

    Post summary

    CVE‑2026‑32201 is actively exploited in the wild, with 1,370 unpatched IPs identified, but no PoC, exploit tool, or patch information is provided.

    290942.3K
    21.9K followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-32201: Microsoft SharePoint Server Spoofing Vulnerability, 6.5 rating ❗️ Improper input validation in Microsoft SharePoint Server allows an unauthorized attacker to perform spoofing over a network and view sensitive internal data or make unauthorized changes. This vulnerability is already being actively exploited in the wild! 👉 https://nt.ls/DjQpd

    Post summary

    The post communicates that CVE-2026-32201, a spoofing flaw in Microsoft SharePoint Server, is already being actively exploited in the wild, with no PoC, exploit code, patch, or mitigation details provided.

    0501451.6K
    7.5K followersView on X
  • connect24h@connect24h
    Active Exploitation

    件数多すぎ問題。 初動順を誤ると、今週はかなり痛い。CSIRTが先に潰す5件。①実悪用中のon-prem SharePoint 3件(CVE-2026-32201/45659/56164)。外部公開停止→patch→侵害hunt→IIS machine key rotation。②未修正Windows zero-day「LegacyHive」。全supported版でPoC動作する権限昇格。③OkoBot。25か国超・数百人、Ledger/Trezor正規app内へseed phrase窃取画面をinject。Apple Sync task、outbound SSH、termsrv.dll改変をhunt。④LLM支援TuxBot v3。17 architecture、1,496組のcredential、30超のIoT familyを狙う。Telnet/SSH/ADBを閉じる。⑤23andMe。690万人漏えいで42当局と1,800万ドル和解。rate limitと異常login監視の欠落が制裁につながった。\n保存して、外部公開資産→endpoint IoC→IoT認証→log保全の順で回してほしい

    Post summary

    The message outlines five CSIRT‑managed incidents, including actively exploited SharePoint servers with several CVEs and a Windows zero‑day PoC, along with mitigation steps such as patching and key rotation.

    110961.7K
    6.8K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨 Upozorňujeme na aktivně zneužívanou zranitelnost v Microsoft SharePoint, CVE-2026-32201. Tato zranitelnost je způsobena nedostatečnou validací vstupů v komponentách SharePointu, což umožňuje neautorizovanému útočníkovi provádět spoofingové útoky přes síť. Přestože má zranitelnost střední závažnost (CVSS 6.5), je aktivně zneužívána v reálných útocích a byla zařazena agenturou CISA do katalogu Known Exploited Vulnerabilities (KEV). Úspěšné zneužití může vést k neoprávněnému zobrazení a úpravám důvěrných informací v prostředí SharePoint, a to bez nutnosti autentizace útočníka. Podle bezpečnostních výzkumníků probíhá koordinovaná průzkumná kampaň z několika IP adres a hostingových providerů, která cílí na instance SharePointu vystavené do sítě. Microsoft uvedl, že zranitelnost byla mitigována a publikoval dodatečné pokyny, přičemž v kontextu opravy upozornil i na další související chyby v oblasti zpracování vstupů. 📌Doporučujeme aktualizovat na verze Microsoft SharePoint Server Subscription Edition - 16.0.19725.20210, Microsoft SharePoint Server 2019 - 16.0.10417.20114 a Microsoft SharePoint Enterprise Server 2016 - 16.0.5548.1003.

    Post summary

    CVE-2026-32201 is an actively exploited Microsoft SharePoint vulnerability caused by insufficient input validation, leading to unauthorized spoofing and data modification. Microsoft has issued mitigation guidance and update recommendations to remediate the issue.

    030921.4K
    4.2K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/14追加) 🛡️No.1568 CVE-2009-0238 Microsoft Office Remote Code Execution Vulnerability ==================================== ✅概要 ・深刻度:8.8 重要 (CVSS Base) / CISA-ADP ・種別:境界外書き込み (CWE-119) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Microsoft Officeにおいて、メモリ処理の不備に起因する脆弱性が存在。事前認証されていない攻撃者により、細工したOfficeファイルをユーザに開かせることで、メモリ破損を引き起こさせ、ユーザー権限で任意コードを実行される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:中 ✅攻撃前提条件 ・ユーザが細工されたOfficeファイルを開く必要がある ✅悪用時影響 ・任意コード実行 ・情報の取得、改ざん、システム影響 ✅悪用事例等に関する公開情報 ・PoC/Exploit:解析情報等あり ・ITW:確認ずみ ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2009-0238 https://learn.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-017 🛡️No.1569 CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation Vulnerability ==================================== ✅概要 ・深刻度:6.5 注意 (CVSS Base) / Microsoft Corporation (CNA) ・種別:入力の検証の不備 (CWE-20) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Microsoft SharePoint Serverにおいて、入力の検証の不備に起因する脆弱性が存在。事前認証されていない攻撃者により、細工されたリクエストを介して、不正な入力を処理される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅攻撃前提条件 ・SharePoint Serverへのネットワークアクセスが可能 ✅悪用時影響 ・情報の取得 ・情報の改ざん ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 --- ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-32201 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201 https://www.cisa.gov/news-events/alerts/2026/04/14/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    The post announces that two CVEs have been added to CISA’s KEV catalog, confirms active exploitation of CVE-2009-0238, provides PoC references, technical details, and links to vendor guidance while noting no evidence of false positives.

    020755.5K
    43.5K followersView on X
  • Cristian Borghello@SeguInfo
    General

    Más de 1.300 servidores SharePoint expuestos a la vulnerabilidad CVE-2026-32201 de abril http://blog.segu-info.com.ar/2026/04/mas-de-1300-servidores-sharepoint.html

    Post summary

    The post reports that more than 1,300 SharePoint servers are exposed to CVE‑2026‑32201, but offers no technical, exploit, or patch information.

    030821.1K
    38.3K followersView on X
  • 𝔇𝔢𝔯 ℭ𝔥𝔲𝔡@der_chuddie
    Patch

    @Pirat_Nation Microsoft released a new patch to fix 167 street shitters code blocks. >CVE-2026-32201: shitting on Sharepoint >CVE-2026-33825: shitting on Defender Run flush.exe with admin rights to install patch

    Post summary

    Microsoft released a patch to address CVE‑2026‑32201 and CVE‑2026‑33825 affecting SharePoint and Defender, with instructions to install the update.

    0001022.7K
    126 followersView on X
  • Netlas.io@Netlas_io
    Active Exploitation

    CVE-2026-56164 and other: EoP and another exploitable vulnerabilities in Microsoft SharePoint Server, 5.3 rating 🔥 A new Elevation of Privilege vulnerability in Microsoft SharePoint Server has been added to the CISA KEV, along with two previously disclosed vulnerabilities (CVE-2026-45659 & CVE-2026-32201). Attackers can chain them to gain access to SharePoint Server instances, steal IIS machine keys, and deploy malware. 🔥 All three are being actively exploited in the wild! 👉 https://nt.ls/oGZ1j

    Post summary

    Three upgraded SharePoint Server CVEs—including CVE‑2026‑56164—are listed in the CISA KEV and reportedly being exploited in the wild to elevate privileges, steal keys, and deploy malware.

    10082931
    7.7K followersView on X
  • Horizon Secured@horizon_secured
    Disclosure

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝗽𝗿𝗶𝗹 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 This month brings 2 Zero-Days and 2 additional 9.0+ vulnerabilities. 𝗠𝗮𝗶𝗻 𝗶𝘀𝘀𝘂𝗲𝘀 𝘁𝗼 𝘄𝗮𝘁𝗰𝗵: • CVE-2026-33825 – Microsoft Defender EoP (BlueHammer) • CVE-2026-32201 – SharePoint spoofing • CVE-2026-33824 – Windows IKE RCE • CVE-2026-26149 – Power Apps security bypass Full breakdown in this month’s Horizon Alert. #PatchTuesday #CyberSecurity #ZeroDay #Vulnerability #Microsoft

    Post summary

    The alert announces four newly discovered zero‑day vulnerabilities affecting Microsoft Defender, SharePoint, Windows IKE, and Power Apps, but does not provide proof‑of‑concepts, exploitation tools, or patch information.

    010911.2K
    2.5K followersView on X
  • Modat@modat_magnify
    Active Exploitation

    ⚠️Microsoft SharePoint – Unauthenticated Privilege Escalation (CVSS 9.8, CISA KEV, Actively Exploited) CISA has added CVE-2026-56164 to its KEV catalogue following evidence of active exploitation, grouping it with two other actively exploited SharePoint vulnerabilities, CVE-2026-32201 and CVE-2026-45659, all used against internet-exposed on-premises servers. CVE-2026-56164 is a missing-authentication-for-critical-function flaw in on-premises Microsoft SharePoint Server that allows an unauthenticated attacker to elevate privileges over the network, with no credentials and no user interaction required. In observed attacks, it is chained with the other two flaws to achieve remote code execution and post-exploitation activity, including theft of IIS machine keys and the use of deserialization techniques to gain persistence and deploy malware. Affected: SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition (all supported on-premises versions). Mitigation: Apply Microsoft's July 2026 security updates immediately, enable AMSI integration for SharePoint web applications, and avoid direct internet exposure. Federal agencies must remediate by July 17, 2026, per BOD 26-04. Modat Magnify Query: technology="Microsoft SharePoint" The platform: https://magnify.modat.io/ Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164 #Modat #ModatMagnify #threatintel #vulnerability #CVE202656164 #Microsoft #SharePoint #PrivEsc #infosec #KEV

    Post summary

    Microsoft SharePoint vulnerability CVE-2026-56164 is actively exploited in the wild, part of CISA's KEV list, with high severity and immediate remediation steps urged.

    021521.3K
    1.8K followersView on X
  • Barnacules Nerdgasm@Barnacules
    Patch

    Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201) - Blog | Tenable® https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201

    Post summary

    The text announces that Microsoft’s April 2026 Patch Tuesday contains a patch for CVE-2026-32201 among 163 other CVEs, with no mention of PoC, exploit code, or active exploitation.

    01042981
    100.6K followersView on X
  • ヴェロ🛡🖥セキュリティVTuber@VELO_ch
    Active Exploitation

    今日は毎月恒例「Windows Update」の日です。 https://gigazine.net/news/20260415-windows-update/ 特に注意したいのは、実際に悪用が確認されている Microsoft SharePoint Server のなりすまし脆弱性 (CVE-2026-32201)。 企業・組織で利用している場合は優先度高めで早急な更新を推奨します。 個人利用でも、Defender利用環境では優先度高め。 市販ソフト利用時は相対的に少し下がる可能性はありますが、Windows全体の更新も含まれるため早めの更新をおすすめします。

    Post summary

    The article alerts that CVE‑2026‑32201, a spoofing vulnerability in Microsoft SharePoint Server, is actively exploited, urging users—especially businesses—to apply updates promptly.

    11031400
    2.5K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    CISA adds Microsoft SharePoint spoofing (CVE-2026-32201) and legacy Office RCE (CVE-2009-0238) to its KEV Catalog. Remediation deadline: April 28, 2026. #CISA #KEV #SharePoint #CyberSecurity #InfoSec #PatchNow #MicrosoftOffice https://securityonline.info/cisa-kev-sharepoint-spoofing-legacy-office-rce-alert/ https://t.co/yQO1zfmBHj

    Post summary

    The tweet announces that CISA has added Microsoft SharePoint spoofing (CVE-2026-32201) and legacy Office RCE (CVE-2009-0238) to its KEV catalog, setting a remediation deadline of April 28, 2026, indicating that patches are needed.

    02031488
    12.3K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Microsoft’s April 2026 Patch Tuesday fixes 163 flaws, including an exploited SharePoint spoofing bug (CVE-2026-32201). Patch by April 28 per CISA mandate. #PatchTuesday #SharePoint #CVE202632201 #CISA #Microsoft #CyberSecurity #InfoSec https://securityonline.info/microsoft-patch-tuesday-april-2026-sharepoint-exploit/ https://t.co/FkVjlfjb8H

    Post summary

    Microsoft’s April 2026 Patch Tuesday includes a fix for CVE-2026-32201, a SharePoint spoofing bug that has already been exploited, and users are urged to apply the patch by April 28 under a CISA mandate.

    12030324
    12.3K followersView on X
  • Michael Martino@battista212
    Active Exploitation

    CISA added CVE-2009-0238 (Microsoft Office RCE) and CVE-2026-32201 (SharePoint input validation) to Known Exploited Vulnerabilities — both under active exploitation. FCEB agencies hit remediation deadline under BOD 22-01. If you're running either, patch now. #Cybersecurity #InfoSec

    Post summary

    CISA has identified CVE-2009-0238 and CVE-2026-32201 as actively exploited vulnerabilities, urging affected agencies to apply patches promptly.

    22020727
    240 followersView on X
  • University of ZERO@zerotalktoai
    Active Exploitation

    CISA Adds Two Known Exploited Vulnerabilities to Catalog 04/14/2026 2:30 PM EST CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2009-0238 Microsoft Office Remote Code Execution Vulnerability CVE-2026-32201 Microsoft SharePoint Server Improper Input Validation Vulnerability

    Post summary

    CISA announced two CVEs in its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation, but provides no PoC, exploit code, or patch information.

    0104181
    1.6K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more