SharePoint Zero-Day CVE-2026-32201: Over 1,300 Servers Still Exposed
Microsoft's SharePoint Server is under active exploitation via CVE-2026-32201, a spoofing vulnerability that allows unauthenticated attackers to compromise enterprise systems over the network. Tracked with a CVSS score of 6.5, the vulnerability stems from improper input validation in Microsoft Office SharePoint that enables network-based spoofing attacks. Microsoft patched the flaw during its April 2026 Patch Tuesday release, but security researchers have identified over 1,300 SharePoint servers still exposed to the public internet without the security update applied. The vulnerability has evolved from spoofing to enabling remote code execution in some configurations, significantly raising the risk profile. Organizations running SharePoint Server — particularly those with internet-facing deployments — are urged to apply patches immediately and review access logs for indicators of compromise. The exploit is being tracked by multiple threat intelligence firms, with evidence of both opportunistic scanning and targeted attacks against enterprise environments. This incident underscores the persistent gap between patch availability and actual deployment, a challenge that affects organizations worldwide including across the MENA region where on-premises SharePoint deployments remain common in government and enterprise settings.
This is a textbook example of the patching gap that plagues enterprises globally. For MENA organizations running on-premises SharePoint, this vulnerability is particularly urgent — many regional enterprises have slower patch cycles and limited security operations capacity.
What should organizations do about CVE-2026-32201?
Immediately apply Microsoft's April 2026 Patch Tuesday updates to all SharePoint servers, restrict internet exposure where possible, and audit access logs for any suspicious activity dating back to before the patch was available.