A medium-severity SharePoint flaw can still expose confidential data and let attackers alter it. The standard response of treating a 6.5 score as lower priority misses that network spoofing in a collaboration platform can become direct access to sensitive content. Microsoft says CVE-2026-32201 comes from improper input validation in SharePoint and can let an unauthorized attacker conduct spoofing activity over a network. A successful attack can let a hacker view and make changes to confidential information, and CISA added the flaw to its Known Exploited Vulnerabilities catalog after researchers reported coordinated reconnaissance across four IPs and four hosting providers from April 1 to April 11. The pattern points to broad scanning for reachable SharePoint instances, not a one-off probe. That raises the odds that exposed servers will be found quickly and then targeted for data access.
Part of the PlainSec briefing for 2026-04-16