CVE-2026-32201: listed in the CISA KEV catalog
CVE-2026-32201 · CVSS 6.5 MEDIUM · KEV 2026-04-14 · patch available
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Is CVE-2026-32201 exploited?
- Listed in the CISA KEV catalog on 2026-04-14.
- Federal remediation due 2026-04-28.
- Past that date by 109 days.
- Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
What PlainSec published about CVE-2026-32201
Primary sources
What this record does not say
- No EPSS score.
- No affected package data.
KEV and EPSS are re-checked daily. Record last updated 2026-08-11.