Microsoft issued an urgent security update addressing an actively exploited zero-day vulnerability in its SharePoint Server platform.
The flaw, officially tracked as CVE-2026-32201, allows unauthenticated attackers to conduct network-based spoofing attacks.
Because threat actors are already exploiting this weakness in the wild, system administrators must apply the available patches immediately to protect their corporate networks.
Technical Vulnerability Details
According to the Microsoft Security Response Center disclosure, CVE-2026-32201 carries an “Important” severity rating and a CVSS 3.1 base score of 6.5 out of 10.
The root cause of the vulnerability stems from improper input validation (CWE-20) within the Microsoft Office SharePoint architecture.
Key technical characteristics of the exploit include:
- Attack Vector:Â The flaw is exploitable remotely over a network connection.
- Complexity:Â The attack complexity is low, making it relatively easy for threat actors to execute.
- Authentication:Â No special privileges or user interaction are required to launch a successful attack.
- Exploit Status:Â Microsoft has confirmed that functional exploit code exists and active exploitation has already been detected.
While a CVSS score of 6.5 might seem moderate compared to critical remote code execution flaws, the active exploitation of this zero-day makes it a high-priority threat.
If an attacker successfully leverages this spoofing vulnerability, they can compromise the targeted server in two primary ways.
First, attackers can view sensitive data, resulting in a low-level loss of system confidentiality. Second, they can make unauthorized changes to disclosed information, causing a low-level impact on data integrity.
However, Microsoft’s advisory notes that attackers cannot limit access to the system resources, meaning server availability remains completely unaffected.
Microsoft has released official security updates to resolve the improper input validation issue.
To protect their environments, organizations must download and install the appropriate Knowledge Base (KB) updates for their specific deployments.
The vulnerability impacts the following software versions:
- Microsoft SharePoint Server Subscription Edition (Update KB5002853)
- Microsoft SharePoint Server 2019Â (Update KB5002854)
- Microsoft SharePoint Enterprise Server 2016Â (Update KB5002861)
Administrators running any of these supported versions should prioritize deploying these patches.
Due to the confirmed in-the-wild exploitation, delaying these security updates leaves enterprise networks highly vulnerable to ongoing spoofing attacks and potential data exposure.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





