Vulnerabilities · 153 days ago

SharePoint Zero-Day Lands in Microsoft’s Huge April Batch

The immediate problem is not just the SharePoint flaw. It is the size of the patch set, which turns one urgent zero-day into a triage problem across 165 Microsoft CVEs and 80 Edge/Chromium fixes already shipped this month. Defenders have to separate active exploitation from the rest of the noise fast, and that is getting harder as vulnerability reports keep rising.

Microsoft says CVE-2026-32201 is being exploited in the wild. It is a SharePoint spoofing issue caused by improper input validation, and CISA has already added it to the KEV catalog. Microsoft also flagged 19 other flaws as more likely to be exploited, including issues in Defender, Windows, Office, Active Directory, TCP/IP, and other core components.

The broader risk is that AI-assisted reporting is inflating monthly patch volume faster than most teams can absorb it. That does not change the exploitability of any single bug, but it does raise the odds that a real zero-day gets buried in a release cycle that is already stretched thin.

CVE-2026-32201

NVD KEV

Known exploited · CISA KEV

CVSS 6.5 MEDIUM: improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a… Microsoft patch: 5002861.

Patch available KB5002861 Download →

CISA federal remediation date Apr 28

Timeline

Sources

5 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-04-15

Editions

Related stories