Vulnerabilities & Exploits · Web App Attack

SharePoint Flaw Lets Attackers Spoof and Read Data

A medium-severity SharePoint flaw can still expose confidential data and let attackers alter it. The standard response of treating a 6.5 score as lower priority misses that network spoofing in a collaboration platform can become direct access to sensitive content.

Microsoft says CVE-2026-32201 comes from improper input validation in SharePoint and can let an unauthorized attacker conduct spoofing activity over a network. A successful attack can let a hacker view and make changes to confidential information, and CISA added the flaw to its Known Exploited Vulnerabilities catalog after researchers reported coordinated reconnaissance across four IPs and four hosting providers from April 1 to April 11.

The pattern points to broad scanning for reachable SharePoint instances, not a one-off probe. That raises the odds that exposed servers will be found quickly and then targeted for data access.

1 source · Apr 15

CVE-2026-32201

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a… Microsoft patch: 5002861.

Patch available KB5002861 Download →

CISA federal remediation date Apr 28

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-04-16

Every edition of this story: SharePoint Flaw Lets Attackers Spoof and Read Data

More from today