Executive brief
Microsoft SharePoint, a widely used platform for corporate collaboration and document management, is affected by a security flaw that allows unauthorized individuals to perform spoofing attacks. An attacker could exploit this to impersonate legitimate services or users, potentially leading to unauthorized access to internal information or the delivery of deceptive content to employees. This vulnerability has been identified as being actively exploited in the wild, making immediate patching a priority for maintaining organizational trust and data integrity.
Technical details
A vulnerability exists in Microsoft SharePoint Server due to improper input validation (CWE-20). An unauthenticated attacker can exploit this flaw over the network to perform spoofing attacks. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition. While the CVSS score is 6.5 (Medium), the vulnerability is notable for its inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Microsoft has released security updates to address this issue; administrators should apply the latest patches for their specific SharePoint version.
Affected products
- Microsoft SharePoint Server 2016 Enterprise Edition
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition up to (excluding) 16.0.19725.20210
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Microsoft and NVD published details
- 2026-04-14: kev added: Added to CISA KEV catalog due to active exploitation