SharePoint Zero-Day Lands in Microsoft’s Huge April Batch
The immediate problem is not just the SharePoint flaw. It is the size of the patch set, which turns one urgent zero-day into a triage problem across 165 Microsoft CVEs and 80 Edge/Chromium fixes already shipped this month. Defenders have to separate active exploitation from the rest of the noise fast, and that is getting harder as vulnerability reports keep rising.
Microsoft says CVE-2026-32201 is being exploited in the wild. It is a SharePoint spoofing issue caused by improper input validation, and CISA has already added it to the KEV catalog. Microsoft also flagged 19 other flaws as more likely to be exploited, including issues in Defender, Windows, Office, Active Directory, TCP/IP, and other core components.
The broader risk is that AI-assisted reporting is inflating monthly patch volume faster than most teams can absorb it. That does not change the exploitability of any single bug, but it does raise the odds that a real zero-day gets buried in a release cycle that is already stretched thin.
CVSS 6.5 MEDIUM: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a… Microsoft patch: 5002861.
JPCERT-AT-2026-0010 JPCERT/CC 2026-04-15 Microsoft Corporation April 2026 Security Updates https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-Apr According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the…
The vendor disclosed one actively exploited zero-day vulnerability in Microsoft Office SharePoint that allows attackers to view information and make changes to disclosed information.