{"id":12306,"date":"2026-04-22T10:03:41","date_gmt":"2026-04-22T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/22\/1370-microsoft-sharepoint-servers-vulnerable-to-spoofing-attacks-exposed-online\/"},"modified":"2026-04-22T10:03:41","modified_gmt":"2026-04-22T10:03:41","slug":"1370-microsoft-sharepoint-servers-vulnerable-to-spoofing-attacks-exposed-online","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/22\/1370-microsoft-sharepoint-servers-vulnerable-to-spoofing-attacks-exposed-online\/","title":{"rendered":"1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online"},"content":{"rendered":"<p>    1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical spoofing vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, remains unpatched on over 1,370 internet-facing IP addresses worldwide, according to fresh scanning data from the Shadowserver Foundation, even as the flaw sits on CISA\u2019s Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation in the wild.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/sharepoint-server-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2026-32201 is rooted in improper input validation<\/a> (CWE-20) within Microsoft Office SharePoint Server\u2019s request processing component. By sending specially crafted network requests, an unauthenticated remote attacker can bypass authentication checks and perform spoofing attacks impersonating legitimate users to access or manipulate sensitive organizational data.<\/p>\n<p>Microsoft\u2019s advisory confirms that successful exploitation can allow an attacker to view sensitive information and make changes to disclosed information, though availability is not directly impacted.<\/p>\n<p>The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium severity), but security researchers warn that its real-world danger far exceeds its score.<\/p>\n<p>The attack vector is fully network-based (AV:N), requires low complexity (AC:L), no privileges (PR:N), and no user interaction (UI:N) a dangerous combination for any internet-exposed enterprise collaboration platform.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-microsoft-sharepoint-servers-vulnerable\"><strong>Microsoft SharePoint Servers Vulnerable<\/strong><\/h2>\n<p><a href=\"https:\/\/cybersecuritynews.com\/microsoft-patch-tuesday-april-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft disclosed CVE-2026-32201 on April 14, 2026<\/a>, as part of its April Patch Tuesday update cycle, which addressed a total of 169 vulnerabilities.<\/p>\n<p>The flaw affects on-premises SharePoint Server versions, including 2016, 2019, and Subscription Edition. CISA simultaneously added the vulnerability to its KEV catalog on April 14, citing confirmed evidence of active exploitation, and issued a federal remediation deadline of April 28, 2026.<\/p>\n<p>CISA\u2019s rapid KEV listing moving in lockstep with Microsoft\u2019s patch release signals the severity with which threat actors are actively targeting unpatched SharePoint infrastructure.<\/p>\n<p>This pattern mirrors the 2025 \u201cToolShell\u201d exploitation campaign, in which hundreds of SharePoint customers were targeted via chained SharePoint vulnerabilities CVE-2025-49704 and CVE-2025-49706.cybersecuritydive+1<\/p>\n<p>Shadowserver Foundation scanning data reveals 1,370 unpatched IP addresses still exposed to CVE-2026-32201 as of April 20, 2026, tracked under the <code>http_vulnerable<\/code> and <code>http_vulnerable6<\/code> sources. The geographic breakdown of exposed systems is alarming:<\/p>\n<ul class=\"wp-block-list\">\n<li>North America: 677 (largest share, with the United States accounting for 587 IPs)<\/li>\n<li>Europe: 452<\/li>\n<li>Asia: 144<\/li>\n<li>Oceania: 33<\/li>\n<li>South America: 33<\/li>\n<li>Africa: 31<\/li>\n<\/ul>\n<p>The world map data confirms that the United States bears the highest concentration of vulnerable SharePoint deployments, with Canada contributing an additional 70 exposed IPs. European exposure is also significant, with clusters observed across Germany, France, and the UK.<\/p>\n<p>Despite its \u201cMedium\u201d CVSS rating, CVE-2026-32201 presents a severe risk for any organization running an internet-facing, on-premises SharePoint Server.<\/p>\n<p>The pre-authentication nature of the exploit means no credentials are needed any network-reachable SharePoint instance is a potential target. Exploitation can lead to credential theft, data exfiltration, unauthorized document access, and potential lateral movement into broader enterprise networks.<\/p>\n<h2 class=\"wp-block-heading\" id=\"recommended-mitigations\"><strong>Mitigations<\/strong><\/h2>\n<p>Organizations should take the following immediate steps:<\/p>\n<ul class=\"wp-block-list\">\n<li>Apply Microsoft\u2019s April 2026 Patch Tuesday security updates for all supported SharePoint Server versions (2016, 2019, Subscription Edition).<\/li>\n<li>Audit internet-facing SharePoint deployments and restrict public exposure where possible<\/li>\n<li>Monitor for anomalous authentication activity and spoofed session indicators<\/li>\n<li>Cross-reference CISA\u2019s KEV catalog and prioritize CVE-2026-32201 remediation before the April 28 federal deadline<a href=\"https:\/\/thehackernews.com\/2026\/04\/microsoft-issues-patches-for-sharepoint.html\" target=\"_blank\" rel=\"noreferrer noopener\">.<\/a>\n<\/li>\n<li>Use Shadowserver\u2019s free scanning reports to identify vulnerable assets within your network perimeter.<\/li>\n<\/ul>\n<p>With over a thousand vulnerable systems still exposed more than a week after patch availability, organizations running on-premises SharePoint Server face an urgent window to remediate before threat actors escalate their exploitation campaigns.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/1370-sharepoint-servers-vulnerable\/\">1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/1370-sharepoint-servers-vulnerable\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online A critical spoofing vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, remains unpatched on over 1,370 internet-facing IP addresses worldwide, according to fresh scanning data from the Shadowserver Foundation, even as the flaw sits on CISA\u2019s Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-12306","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12306"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12306"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12306\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12306"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12306"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12306"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}