Skip to content

SharePoint Zero-Day CVE-2026-32201: 1,300+ Servers Still Exposed

Cybersecurity News · Story 3 of 6

Microsoft disclosed CVE-2026-32201 during its April 2026 Patch Tuesday, confirming that a critical spoofing vulnerability in SharePoint Server is being actively exploited in the wild. The flaw allows unauthenticated attackers to perform network-based spoofing attacks that can escalate to remote code execution on enterprise SharePoint deployments. What makes this particularly alarming is the scale of exposure: security researchers identified more than 1,300 SharePoint servers facing the public internet that remain unpatched, despite the fix being available for over a month. Microsoft addressed 169 vulnerabilities in that same Patch Tuesday cycle, but CVE-2026-32201 stands out as the only confirmed zero-day under active exploitation. Organizations running SharePoint Server versions exposed to the internet — particularly those hosting collaboration portals, intranets, or document management systems — are at immediate risk. The attack vector requires no authentication and no special privileges, making it accessible to unsophisticated threat actors. For organizations across MENA where on-premises SharePoint deployments remain common in government and enterprise environments, this is a critical patching priority. Microsoft's MSRC has published detailed guidance, and security firms recommend immediately restricting internet exposure of SharePoint servers as a stopgap while patching proceeds.

Analysis
Live

Over 1,300 unpatched internet-facing servers a month after patch release shows the persistent gap between disclosure and remediation in enterprise environments. For MENA organizations still relying on on-premises SharePoint, this is an urgent infrastructure hygiene issue.

Frequently Asked Questions
How do I check if my SharePoint server is affected?

Check your SharePoint Server version against Microsoft's MSRC advisory for CVE-2026-32201. If your server is exposed to the internet and hasn't been patched since April 2026, it is likely vulnerable. Immediately restrict internet access and apply the latest security updates.