Attackers exploited a spoofing vulnerability in Microsoft SharePoint Server before Redmond issued a fix as part of April's mega Patch Tuesday. The monthly patch party included a whopping 165 new Microsoft CVEs. And the bug under active exploitation, CVE-2026-32201, is due to improper input validation in SharePoint that allows an unauthorized attacker to perform spoofing over a network. This could allow someone to view sensitive information and make changes to disclosed information. "By exploiting this flaw, an attacker can manipulate how information is presented to users, potentially tricking them into trusting malicious content," Mike Walters, president and cofounder of patch management provider Action1, told us, adding that this bug can be abused in phishing attacks, unauthorized data manipulation, or social engineering campaigns that lead to further compromise. "The flaw lets attackers fake trust at scale: what looks legitimate may actually be a carefully crafted deception," Walters said. "It can be used to deceive employees, partners, or customers by presenting falsified information within trusted SharePoint environments." Redmond did not provide any details about how this security hole is being abused in the wild - nor who disclosed it. Maybe Mythos, or another bug-hunting AI? The Register asked Microsoft to provide additional information, and here's what we received: "Each year, MSRC processes thousands of vulnerability reports from Microsoft and external researchers, s...
Microsoft's massive Patch Tuesday: It's raining bugs
The Register
·Jessica Lyons
·Published Apr 14, 2026
·Updated
Affected Software
2 affected components
Microsoft SharePoint Server
Microsoft Defender
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Microsoft's April Patch Tuesday, which included fixes for 165 new CVEs and addressed a critical spoofing vulnerability in SharePoint Server.
2
What security implications are discussed in the article?
The article highlights the exploitation of a spoofing vulnerability in SharePoint Server that was active prior to the release of the patch.
3
What products or software are affected by the vulnerabilities mentioned?
The vulnerabilities affect Microsoft SharePoint Server and Microsoft Defender as part of the April Patch Tuesday updates.
4
How many new CVEs were included in this month's patch?
The article mentions that Microsoft's April Patch Tuesday included a total of 165 new CVEs.
5
Why is it important for users to apply the latest patches?
Applying the latest patches is crucial to protect against actively exploited vulnerabilities and to enhance overall security.