About:
CVE-2026-32201 is an improper input validation vulnerability affecting Microsoft SharePoint Server. The flaw allows an authenticated attacker to exploit insufficient validation of user-supplied input to perform unauthorized actions.
An attacker can send crafted requests to a vulnerable SharePoint server to manipulate content, access sensitive data, or interact with the application in unintended ways. While the CVSS score is moderate, the impact can be significant in environments with broad access or exposed SharePoint instances.
This vulnerability is actively exploited in the wild and has been added to CISA’s Known Exploited Vulnerabilities catalog.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
Identifier: CVE-2026-32201
CVSS Score: 6.5 (CVSS v3.1)
PoC or Exploitation:
CVE-2026-32201 has been identified as actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog.
Update/ Patch:
Mitigation Recommendation: