CVE-2026-32201 is an improper input validation vulnerability in Microsoft Office SharePoint that enables unauthorized attackers to perform spoofing attacks over a network without requiring authentication or user interaction. The vulnerability has a CVSS score of 6.5 (Medium) with a network-based attack vector and low complexity, resulting in limited confidentiality and integrity impacts. This vulnerability is actively being exploited in the wild, as indicated by its inclusion in the Known Exploited Vulnerabilities catalog, and carries a FAUCET Risk Score of 83.0 out of 100, indicating elevated concern despite its moderate baseline severity rating. The EPSS score of 0.0794 suggests this threat ranks higher than approximately 92% of all documented CVEs in terms of exploitation probability. Organizations running affected SharePoint instances should prioritize patching to mitigate the active exploitation risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.0.19725.20210CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.