Medium (6.5) Actively Exploited

SharePoint spoofing exploited in the wild (CVE-2026-32201) [PoC]

CVE-2026-32201

Attackers send spoofed network packets to Microsoft SharePoint Servers (on-premises) to bypass security controls. Apply the April 2026 Patch Tuesday update immediately.

Affected: Microsoft Sharepoint Server

Actively exploited in the wild - CVE-2026-32201 is a medium spoofing vulnerability in Microsoft SharePoint Server (on-premises) that lets an unauthenticated attacker disguise malicious traffic as legitimate, potentially tricking users and bypassing network defenses. Apply the April 2026 security updates immediately.

Overview

A vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, allows an unauthenticated attacker to perform spoofing attacks over a network. This flaw is notable because it is confirmed to be under active, widespread exploitation, as cataloged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in its Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Details

The vulnerability stems from improper input validation within SharePoint. An attacker can exploit this by sending specially crafted network packets to a vulnerable SharePoint server. Crucially, the attack requires no user interaction and no prior authentication, making it easy to launch. The CVSS v3.1 base score is 6.5 (Medium), with the attack vector rated as Network and both attack complexity and privileges required rated as Low and None, respectively.

Impact

Successful exploitation allows an attacker to perform spoofing. In practice, this could enable them to disguise malicious network traffic as legitimate, potentially bypassing security controls, tricking users, or manipulating data flows within the SharePoint environment. While not a direct code execution flaw, spoofing can be a critical first step in a broader attack chain, leading to data theft, credential harvesting, or further network compromise.

Affected Products

This vulnerability affects on-premises Microsoft SharePoint Server versions. Microsoft 365 SharePoint Online is not affected. Administrators should review the official Microsoft Security Update Guide for April 2026 for specific version details.

Remediation and Mitigation

The primary remediation is to apply the security updates provided by Microsoft in its April 2026 Patch Tuesday release. Organizations should prioritize this update immediately due to confirmed active exploitation.

If immediate patching is not possible, consider the following mitigation strategies:

  • Restrict network access to SharePoint servers, especially from untrusted networks like the internet, using firewall rules.
  • Implement network segmentation to limit the potential lateral movement of an attacker who gains an initial foothold.
  • Monitor network traffic for anomalous patterns or spoofing attempts.

Security Insight

The active exploitation of this SharePoint spoofing flaw highlights a trend where attackers increasingly target collaboration platforms as initial access vectors. Similar to how threat groups like APT28 have hijacked infrastructure to steal credentials, this vulnerability could be used to establish a deceptive foothold within an organization’s internal network, facilitating more severe follow-on attacks. It underscores the critical need to treat “Medium” severity vulnerabilities with high urgency when they appear on the KEV list.

Update - May 2026

CVE-2026-32201 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on 2026-05-07. The EPSS score has decreased marginally from 0.07937 to 0.0687, but remains in the 91st percentile - indicating broad attacker tooling integration despite a slight probability shift. Microsoft has not issued a standalone patch; instead, SharePoint Server Subscription Edition and SharePoint 2019 received cumulative security updates on 2026-05-05 that include a fix for this spoofing vector. Organizations still on unsupported builds should migrate immediately. No additional CVEs have been disclosed in the same family, though threat actors targeting SharePoint in April 2026 attacks show correlation with CVE-2026-32198 (privilege escalation) chained in observed intrusions. Active exploitation detections from industry partners show scanning for crafted POST requests to /_layouts/15/start.aspx with anomalous form payloads. Defenders should filter URI paths containing /start.aspx with unvalidated Source parameters, enforce Content Security Policy headers on all SharePoint pages, and validate patch status using Get-SPProduct -Local. Prioritize KEV-listed vulnerabilities for emergency remediation within 24 hours per BOD 25-01 guidance.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
B1tBit/CVE-2026-32201-exploit

A spoofing vulnerability exists in Microsoft SharePoint Server due to improper input validation. An unauthenticated attacker can send a specially crafted HTTP request to inject malicious JavaScript (r

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.