CVE-2026-32201

9.5 CISA KEV

Microsoft · SharePoint Server

Improper input validation in Microsoft SharePoint Server allows an unauthenticated attacker to perform identity spoofing over a network.

Executive summary

A critical input validation vulnerability in Microsoft SharePoint Server is currently being exploited in the wild to perform identity spoofing and potentially pivot into integrated systems.

Vulnerability

This vulnerability involves improper input validation that allows an unauthenticated, network-reachable attacker to influence content rendering. This effectively enables identity spoofing within the SharePoint trust model.

Business impact

Successful exploitation allows an attacker to manipulate how content is rendered, causing malicious data to appear as legitimate system output. With a CVSS score of 9.5, this flaw presents a high risk of identity spoofing and unauthorized data manipulation. The ability to pivot into integrated systems significantly increases the potential for lateral movement and broader compromise of the corporate environment.

Remediation

Immediate Action: Apply the security updates KB5002861, KB5002854, or KB5002853 depending on the specific SharePoint version installed.

Proactive Monitoring: Review SharePoint logs for suspicious traffic or rendering anomalies that deviate from established baseline behaviors.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to inspect and filter malicious input payloads targeting SharePoint endpoints.

Exploitation status

Public Exploit Available: Yes (a public proof-of-concept exists on GitHub).

Analyst recommendation

Given the active exploitation and the critical nature of the SharePoint platform in enterprise environments, immediate patching is required. Organizations should treat this as a high-priority remediation task to secure their trust models against spoofing attacks.

More Microsoft CVEs

Sources