惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
量子位
T
Tailwind CSS Blog
Vercel News
Vercel News
I
InfoQ
Stack Overflow Blog
Stack Overflow Blog
U
Unit 42
Engineering at Meta
Engineering at Meta
L
LangChain Blog
大猫的无限游戏
大猫的无限游戏
D
Docker
博客园_首页
P
Proofpoint News Feed
月光博客
月光博客
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Martin Fowler
Martin Fowler
腾讯CDC
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Medium-severity flaw in Microsoft SharePoint exploited
2026-04-15 · via Cybersecurity Dive - Latest News

An article from site logo

The flaw should be taken seriously, despite its relatively low score, according to researchers.

Published April 15, 2026 Updated April 16, 2026

The Microsoft logo is pictures on the technology company's headquarters in Redmond, Washington, on July 3, 2024.

Microsoft's headquarters in Redmond, Washington, on July 3, 2024. A medium-severity flaw in SharePoint is facing exploitation as of April 14, 2026. Getty Images

Researchers warn that hackers are exploiting a medium-grade flaw in Microsoft SharePoint. 

The vulnerability, tracked as CVE-2026-32201, stems from improper input validation in SharePoint, which allows an unauthorized attacker to conduct spoofing activity over a network. The vulnerability has a severity score of 6.5. 

A successful attack can allow a hacker to view and make changes to confidential information, according to a security update from Microsoft.

Researchers from threat intelligence firm Defused posted to X saying they are tracking a coordinated reconnaissance campaign targeting SharePoint across four IPs. 

The activity involves four hosting providers sequenced from April 1 to April 11. 

The Cybersecurity and Infrastructure Security Agency on Wednesday added the vulnerability to the Known Exploited Vulnerabilities catalog.

Microsoft initially offered limited details about the spoofing vulnerability, confirming that it was “mitigated,” according to a spokesperson.

The company later shared some additional guidance, which included mitigation steps. The guidance also referenced a separate cross-site scripting vulnerability in SharePoint, tracked as CVE-2026-20945, which involves the improper neutralization of input during web page generation. The cross-site scripting vulnerability has not been exploited, according to Microsoft..  

The disclosure comes about a month after a prior SharePoint vulnerability, tracked as CVE-2026- 20963, was added to the KEV catalog by CISA. That vulnerability is due to deserialization of untrusted data and has a severity score of 9.8.

Hundreds of SharePoint customers were targeted in a massive exploitation campaign in 2025, dubbed ToolShell. The 2025 campaign involved targeting of a remote code injection flaw, tracked as CVE-2025-49704 and a network spoofing vulnerability, tracked as CVE-2025-49706.

Editor’s note: Updates with additional information from Microsoft.