Friday, September 11, 2026

1,370+ Microsoft SharePoint Servers at Risk of Spoofing Attacks Found Exposed Online

More than 1,370 Microsoft SharePoint servers remain publicly exposed to an actively exploited spoofing vulnerability, putting countless corporate networks at severe risk.

Identified by threat intelligence researchers at The Shadowserver Foundation, these unpatched systems are vulnerable to sophisticated attacks that allow unauthorized individuals to bypass security protocols and compromise network integrity.

The vulnerability, officially tracked as CVE-2026-32201, stems from improper input validation in Microsoft SharePoint.

Because threat actors are currently exploiting this flaw in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities (KEV) catalog.

Despite these high-level warnings and confirmed exploitation, thousands of organizations have yet to apply the necessary security updates.

Microsoft SharePoint Servers at Risk

The Shadowserver Foundation recently deployed version-based scans across the public internet to identify vulnerable SharePoint endpoints.

Their telemetry data shows that exactly 1,370 unique IP addresses still host unpatched servers. While this figure represents a significant security blind spot, it does show a mild improvement over recent weeks.

On April 15, 2026, researchers originally tracked 1,745 vulnerable servers. This indicates that nearly 400 systems have been successfully patched or taken offline over the past week.

Shadowserver continues to share this IP data daily through its Vulnerable HTTP reporting dashboards.

These tools provide geographic and tree map views, allowing regional security teams to monitor the global exposure footprint in real time and identify whether their own assets are at risk.

This security flaw poses a direct threat to enterprise collaboration environments by allowing unauthorized attackers to perform network-level spoofing.

When successful, attackers can manipulate how the server processes data, potentially leading to unauthorized access to sensitive corporate documents or the ability to launch further internal attacks.

Key details of the threat include:

  • Core flaw: Improper input validation allows attackers to craft malicious requests that the SharePoint server processes as legitimate.
  • Active exploitation: The vulnerability is not theoretical; hackers are actively exploiting it in the wild to breach unpatched targets.
  • CISA KEV inclusion: Federal agencies are mandated to patch this flaw immediately, establishing an urgent benchmark for the private sector to follow suit.

The ongoing exposure of these SharePoint servers underscores a critical failure in corporate IT maintenance.

As cybersecurity commentators from VulnTracker noted, when a publicly known, actively exploited flaw remains unresolved on over a thousand internet-facing servers, it ceases to be a mere software issue and becomes a systemic patch management problem.

Enterprises frequently delay patching critical infrastructure to avoid operational downtime, inadvertently creating massive windows of opportunity for cybercriminals.

Administrators must prioritize securing their environments immediately. Security teams should consult the official Microsoft Security Response Center (MSRC) update guide for CVE-2026-32201, apply the latest security patches, and audit their SharePoint logs for any signs of unauthorized spoofing or irregular input validation attempts.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth

Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture...

Hackers Can Turn Vulnerable LiteLLM AI Gateways Into Root Access and Cloud Credential Theft

Nearly one in 10 internet-exposed LiteLLM AI gateways accepted...

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

Skullcandy Dime 3 wireless earbuds have a serious vulnerability...

Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly

Threat actors are increasingly exploiting Active Directory replication mechanisms...

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers

Threat actors are exploiting anticipation around Grand Theft Auto...

Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds

A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O...

Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root

Palo Alto Networks has announced a high-severity buffer overflow...

New Phishing Attack Uses Blob URLs to Hide Malicious Pages From Security Scanners

A phishing campaign that moves the credential-harvesting page out...

Related Articles

Recent News