CVE-2026-32201: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability via Improper Input Validation (Actively Exploited) — Threadlinqs Intelligence
As of 2026-05-30, CVE-2026-32201: Microsoft SharePoint Server Zero-Day Spoofing Vulnerability via Improper Input Validation (Actively Exploited) is a critical-severity zero day threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 14 indicators of compromise.
Threat ID: TL-2026-0366 · Severity: CRITICAL · CVSS: 6.5 · Status: ACTIVE · Category: ZERO_DAY
Attribution: N/A · UNKNOWN
Microsoft SharePoint Server contains a zero-day spoofing vulnerability (CVE-2026-32201, CVSS 6.5) caused by improper input validation (CWE-20) that manifests as cross-site scripting (XSS). Actively
CVE-2026-32201 is a spoofing vulnerability in Microsoft SharePoint Server caused by improper input validation (CWE-20) that allows an unauthorized attacker to perform spoofing over a network. The vulnerability manifests as a cross-site scripting (XSS) flaw, consistent with historical patterns where SharePoint spoofing vulnerabilities have been XSS-based.
The attack requires no authentication, no special privileges, and no user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). An attacker can target internet-facing SharePoint instances directly, injecting malicious JavaScript through improperly sanitized input fields. Successful exploitation enables the attacker to view sensitive information (Confidentiality impact: Low) and make changes to disclosed information (Integrity impact: Low), with no impact on availability.
In practical attack scenarios, malicious JavaScript executing in the browser of a user visiting a compromised SharePoint page can steal session cookies or authentication tokens, enabling account takeover. The XSS foothold opens pathways for phishing redirects, credential harvesting, user impersonation, and pivoting to other internal services. Given SharePoint's role as an enterprise collaboration hub containing sensitive documents, workflows, and integrated access controls, successful exploitation provides a treasure trove of data for threat actors and a vector for lateral movement through weaponized documents.
This vulnerability follows a concerning pattern. As noted by Tenable's Satnam Narang, the last SharePoint Server spoofing vulnerability exploited as a zero-day was CVE-2025-49706 from July 2025, which was part of the ToolShell exploit chain used by ransomware and cyberespionage groups. The recurrence of actively exploited SharePoint spoofing flaws underscores the platform's attractiveness as a high-value target.
Microsoft confirmed active exploitation prior to patch availability, classifying this as a zero-day. Despite the moderate CVSS score of 6.5, the active exploitation status, zero-day nature, and SharePoint's widespread enterprise deployment surface elevate the operational severity. CISA added CVE-2026-32201 to the Known Exploited Vulnerabilities catalog on April 14, 2026, with a binding remediation deadline of April 28, 2026 under BOD 22-01.
Microsoft released security patches as part of the April 2026 Patch Tuesday (which addressed 163-171 CVEs total, including 8 critical and 2 zero-days). The second zero-day was CVE-2026-33825, a Microsoft Defender Elevation of Privilege vulnerability that was publicly disclosed but not yet actively exploited. A related SharePoint spoofing vulnerability, CVE-2026-20945 (CVSS 4.6), was also patched but is not known to be exploited.
Affected versions and their corresponding patches:
- SharePoint Server Subscription Edition: versions prior to 16.0.19725.20210 (KB5002853)
- SharePoint Server 2019: versions prior to 16.0.10417.20114 (KB5002854)
- SharePoint Enterprise Server 2016: versions prior to 16.0.5548.1003 (KB5002861)
Organizations running internet-facing SharePoint servers should treat this as the highest priority patch of the April 2026 cycle. If immediate patching is not feasible, compensating controls include restricting network access to SharePoint, tightening reverse-proxy routing and allowlists, reviewing Content Security Policy headers, and disabling unnecessary external exposure.
Target sectors: government, financial, healthcare, education, technology, defense, energy, legal, manufacturing, telecommunications
Target regions: North America, Europe, Asia-Pacific, Middle East, Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 14 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-32201, T1190, T1189, T1059, T1204, T1505, T1036, T1027, T1539, T1080, T1213