Skip to content

1,300+ SharePoint Servers Still Exposed to Actively Exploited Zero-Day

BleepingComputer · Story 4 of 6

More than 1,300 Microsoft SharePoint servers exposed to the public internet remain unpatched against CVE-2026-32201, a critical spoofing zero-day vulnerability that Microsoft confirmed is being actively exploited in the wild. The flaw was disclosed as part of Microsoft's April 2026 Patch Tuesday, which addressed 169 vulnerabilities total.

CVE-2026-32201 enables unauthenticated attackers to perform network-based spoofing attacks that can compromise enterprise systems. The vulnerability allows remote code execution with no privileges required, making it particularly dangerous for organizations with internet-facing SharePoint deployments. CISA added it to its Known Exploited Vulnerabilities catalog with a remediation deadline of April 28, 2026.

Despite the urgent patch being available for over a month, BleepingComputer reported that over 1,300 servers remain exposed and vulnerable to ongoing attacks. This is particularly concerning for organizations in the Middle East where on-premises SharePoint deployments are common in government and enterprise environments, and where patch management processes may lag behind cloud-first organizations.

Security researchers emphasize that immediate patching is critical. Organizations that cannot patch immediately should restrict internet-facing SharePoint servers, deploy web application firewall rules, and monitor for anomalous authentication activity. The vulnerability affects SharePoint Server 2019, LTSC 2021, and LTSC 2024.

This incident serves as a stark reminder that vulnerability management remains one of the most critical — and most neglected — aspects of enterprise cybersecurity, especially for organizations with legacy on-premises infrastructure.

Analysis
Live

A month after patch release, 1,300+ unpatched servers is unacceptable. This is a textbook example of why patch management remains the weakest link in enterprise security. MENA organizations running on-premises SharePoint should treat this as an immediate incident response priority.

Frequently Asked Questions
Which SharePoint versions are affected by CVE-2026-32201?

SharePoint Server 2019, SharePoint Server Subscription Edition (LTSC 2021), and SharePoint Server Subscription Edition (LTSC 2024) are all affected.

What should organizations do if they can't patch immediately?

Restrict internet-facing access to SharePoint servers, monitor for anomalous authentication activity, and apply the patch as soon as possible. CISA's remediation deadline was April 28, 2026.