Improper input validation in Microsoft SharePoint Server (CVE-2026-32201) — risk of spoofing over a network
Microsoft SharePoint Server, an enterprise information-sharing platform, contains an improper input validation flaw (CWE-20). An attacker may perform spoofing over a network. NVD's Primary assessment is CVSS 6.5 (MEDIUM). CISA added it to the KEV on 2026-04-14, due 2026-04-28.
Key facts
- CVE IDCVE-2026-32201
- CVSS base score6.5 MEDIUM
- CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Affected (vendor / product)Microsoft SharePoint Server
- CWECWE-20
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-04-28 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Improper input validation (CWE-20) in Microsoft SharePoint Server — risk of spoofing over a network.
- NVD's Primary assessment is CVSS 6.5 (MEDIUM; C:L/I:L — limited impact to confidentiality/integrity).
- SharePoint is an enterprise document-sharing and intranet-portal platform where sensitive information gathers.
- Spoofing is a foothold for information theft or unauthorized operations — widening damage combined with other attacks.
- CISA added it to the KEV on 2026-04-14 (due 2026-04-28) = exploited even at MEDIUM.
- Of the 1,687 records held as of 2026-09-01, Microsoft accounts for 386, led by Windows at 172 and Internet Explorer at 36.
1What spoofing is
"Spoofing" is an attack in which an attacker impersonates another legitimate entity (a user or server) to deceive the other party. This flaw stems from insufficient input validation in Microsoft SharePoint Server, said to let an unauthorized attacker perform such spoofing over a network.
SharePoint is widely used as an enterprise document-sharing and intranet-portal platform where much sensitive information gathers, so spoofing can be a foothold for information theft or unauthorized operations.
2A primary CVSS rating of 6.5
NVD's Primary assessment is CVSS 6.5 (MEDIUM), with limited impact to confidentiality and integrity (C:L/I:L). It is not a direct takeover like remote code execution, but spoofing can widen damage when combined with other attacks. SharePoint has had multiple vulnerabilities exploited in the past, and this joined the KEV as one of them.
3Why a medium score still enters KEV
The number is MEDIUM, but CISA's addition to the KEV shows this flaw is being used in real attacks. Weaknesses in a widely used information platform become real targets regardless of a high or low CVSS. The response is prompt updating per Microsoft's guidance.
4What Microsoft's 386 records divide into
Microsoft leads by vendor among the KEV records this site holds as of 2026-09-01. Split by product name, long-serving platform software occupies the top.
Of the 1,687 records held as of 2026-09-01, Microsoft accounts for 386 across 71 product names. For SharePoint, a second spelling, SharePoint Server, accounts for a further five, bringing it to 14. Because one product is recorded under differing names, grouping by product name has to allow for those variants.
SharePoint is widely used as the platform for document sharing and intranet portals, where a great deal of sensitive information gathers.
Why it matters
SharePoint is an enterprise document-sharing and intranet platform where sensitive information gathers. Spoofing is not a direct takeover, but can widen damage through information theft or combination with other attacks. NVD's Primary assessment is MEDIUM (6.5), but being on the KEV means actual exploitation; weaknesses in a widely used information platform become targets regardless of the score. Prompt updating per Microsoft's guidance is the key point.
FAQ
What is spoofing?
Why act if the CVSS is only MEDIUM?
Is this the same as the earlier SharePoint flaw?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).