1,300+ SharePoint Servers Still Exposed to Actively Exploited Zero-Day
More than 1,300 Microsoft SharePoint servers exposed to the public internet remain unpatched against CVE-2026-32201, a critical spoofing zero-day vulnerability that Microsoft confirmed is being actively exploited in the wild. The flaw was disclosed as part of Microsoft's April 2026 Patch Tuesday, which addressed 169 vulnerabilities total.
CVE-2026-32201 enables unauthenticated attackers to perform network-based spoofing attacks that can compromise enterprise systems. The vulnerability allows remote code execution with no privileges required, making it particularly dangerous for organizations with internet-facing SharePoint deployments. CISA added it to its Known Exploited Vulnerabilities catalog with a remediation deadline of April 28, 2026.
Despite the urgent patch being available for over a month, BleepingComputer reported that over 1,300 servers remain exposed and vulnerable to ongoing attacks. This is particularly concerning for organizations in the Middle East where on-premises SharePoint deployments are common in government and enterprise environments, and where patch management processes may lag behind cloud-first organizations.
Security researchers emphasize that immediate patching is critical. Organizations that cannot patch immediately should restrict internet-facing SharePoint servers, deploy web application firewall rules, and monitor for anomalous authentication activity. The vulnerability affects SharePoint Server 2019, LTSC 2021, and LTSC 2024.
This incident serves as a stark reminder that vulnerability management remains one of the most critical — and most neglected — aspects of enterprise cybersecurity, especially for organizations with legacy on-premises infrastructure.
A month after patch release, 1,300+ unpatched servers is unacceptable. This is a textbook example of why patch management remains the weakest link in enterprise security. MENA organizations running on-premises SharePoint should treat this as an immediate incident response priority.
Which SharePoint versions are affected by CVE-2026-32201?
SharePoint Server 2019, SharePoint Server Subscription Edition (LTSC 2021), and SharePoint Server Subscription Edition (LTSC 2024) are all affected.
What should organizations do if they can't patch immediately?
Restrict internet-facing access to SharePoint servers, monitor for anomalous authentication activity, and apply the patch as soon as possible. CISA's remediation deadline was April 28, 2026.