惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Martin Fowler
Martin Fowler
Vercel News
Vercel News
U
Unit 42
Engineering at Meta
Engineering at Meta
aimingoo的专栏
aimingoo的专栏
MyScale Blog
MyScale Blog
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
N
Netflix TechBlog - Medium
GbyAI
GbyAI
F
Fortinet All Blogs
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
M
MIT News - Artificial intelligence
D
Docker
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Microsoft SharePoint vulnerability widely exposed across ...
David Jones · 2026-04-22 · via Cybersecurity Dive - Latest News

An article from site logo

The disclosure comes just weeks after a prior SharePoint flaw was discovered.

Published April 22, 2026

Exterior view of Microsoft's Vancouver office in Canada on December 22, 2023.

Exterior view of Microsoft's Vancouver office on Dec. 22, 2023. A medium-severity vulnerability in Microsoft SharePoint is widely exposed in April 2026. Getty Images

A medium-severity vulnerability in Microsoft SharePoint is vulnerable across about 1,370 IPs worldwide, according to researchers at ShadowServer

Tracked as CVE-2026-32201, the vulnerability is linked to improper input validation in the widely used software. If successfully exploited, an attack would be able to conduct spoofing activity across a network. 

The vulnerability has a severity score of only 6.5, but researchers warn the threat is more serious than the score suggests. 

The Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog. 

Shadowserver researchers said the number of exposed IPs is down from a week ago, when about 1,745 were found to be unpatched. 

The U.S. and Germany are the most widely exposed countries, Shadowserver said. 

Microsoft urged users to immediately apply security updates to address the flaw. The company last week released specific guidance on how to mitigate against vulnerabilities in SharePoint.

In March, a vulnerability tracked as CVE-2026-29963, was added to the KEV catalog by CISA. That vulnerability related to deserialization of untrusted data.