CVE-2026-32201 can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments. This CVE can enable phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise.
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft SharePoint Enterprise Server 2016 | 16.0.0, 16.0.0, 16.0.0, 2019, LTSC 2021, LTSC 2024 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft sharepoint server subscription edition | mitre_affected | 90% |
| microsoft | microsoft sharepoint | mitre_affected | 90% |
Updated description with details on how CVE-2026-32201 can be exploited and confirmed that it is actively exploited.
Updated product to include Microsoft SharePoint Server 2019/LTSC 2021/LTSC 2024, changed severity to CRITICAL, and noted no available exploit.
Updated description with additional details, changed severity to HIGH, added new CWE, and noted that patch information is unclear.
Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.
Initial creation