CVE-2026-32201
CISA KEVAs of 2026-04-14, CVE-2026-32201 is a CVSS 8.8 (HIGH-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 8.9%. Threadlinqs Intelligence tracks 11 threats exploiting it.
Last updated: 2026-04-14
An improper authentication vulnerability in Microsoft SharePoint Server allows an unauthenticated remote attacker to craft a forged request that impersonates an authenticated user, enabling session hijack, unauthorized data access, and subsequent upload of malicious content. This zero-day vulnerability was confirmed as actively exploited in the wild prior to the April 2026 Patch Tuesday release, with exploitation activity concentrated against government, legal, and manufacturing verticals in North America and Europe. Observed post-exploitation behavior includes web-shell deployment (spinstall.aspx variants), credential harvesting from the SharePoint hive, and pivoting to the SQL backend via integrated Windows authentication. Threat actors have been observed chaining this spoofing vulnerability with CVE-2026-33827 (SharePoint Server RCE via deserialization in workflow engine) for full remote code execution.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-287
Exploitation status
CISA KEV-listed (known exploited)
Threats tracking this CVE
- July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days — CRITICAL
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV Catalog — CRITICAL
- CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — CRITICAL
- CVE-2026-56164: Microsoft SharePoint Server Missing-Authentication Vulnerability Actively Exploited, Added to CISA KEV — CRITICAL
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) — CRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation — CRITICAL
- CVE-2026-45659: Microsoft SharePoint Deserialization RCE Actively Exploited, Added to CISA KEV — HIGH
- CVE-2026-45659: Microsoft SharePoint Server Deserialization RCE Added to CISA KEV — HIGH
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE) — CRITICAL
- CVE-2026-32201: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability via Improper Input Validation (Actively Exploited) — CRITICAL
- Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825) — CRITICAL
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.