惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
大猫的无限游戏
大猫的无限游戏
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Vercel News
Vercel News
人人都是产品经理
人人都是产品经理
G
Google Developers Blog
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
雷峰网
雷峰网
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Jina AI
Jina AI
博客园 - 叶小钗
D
DataBreaches.Net
D
Docker
月光博客
月光博客
博客园 - 司徒正美
Last Week in AI
Last Week in AI
有赞技术团队
有赞技术团队
腾讯CDC
酷 壳 – CoolShell
酷 壳 – CoolShell

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
Medium-severity flaw in Microsoft SharePoint exploited
2026-04-15 · via Cybersecurity Dive - Latest News

An article from site logo

The flaw should be taken seriously, despite its relatively low score, according to researchers.

Published April 15, 2026 Updated April 16, 2026

The Microsoft logo is pictures on the technology company's headquarters in Redmond, Washington, on July 3, 2024.

Microsoft's headquarters in Redmond, Washington, on July 3, 2024. A medium-severity flaw in SharePoint is facing exploitation as of April 14, 2026. Getty Images

Researchers warn that hackers are exploiting a medium-grade flaw in Microsoft SharePoint. 

The vulnerability, tracked as CVE-2026-32201, stems from improper input validation in SharePoint, which allows an unauthorized attacker to conduct spoofing activity over a network. The vulnerability has a severity score of 6.5. 

A successful attack can allow a hacker to view and make changes to confidential information, according to a security update from Microsoft.

Researchers from threat intelligence firm Defused posted to X saying they are tracking a coordinated reconnaissance campaign targeting SharePoint across four IPs. 

The activity involves four hosting providers sequenced from April 1 to April 11. 

The Cybersecurity and Infrastructure Security Agency on Wednesday added the vulnerability to the Known Exploited Vulnerabilities catalog.

Microsoft initially offered limited details about the spoofing vulnerability, confirming that it was “mitigated,” according to a spokesperson.

The company later shared some additional guidance, which included mitigation steps. The guidance also referenced a separate cross-site scripting vulnerability in SharePoint, tracked as CVE-2026-20945, which involves the improper neutralization of input during web page generation. The cross-site scripting vulnerability has not been exploited, according to Microsoft..  

The disclosure comes about a month after a prior SharePoint vulnerability, tracked as CVE-2026- 20963, was added to the KEV catalog by CISA. That vulnerability is due to deserialization of untrusted data and has a severity score of 9.8.

Hundreds of SharePoint customers were targeted in a massive exploitation campaign in 2025, dubbed ToolShell. The 2025 campaign involved targeting of a remote code injection flaw, tracked as CVE-2025-49704 and a network spoofing vulnerability, tracked as CVE-2025-49706.

Editor’s note: Updates with additional information from Microsoft.