CVE-2026-32201 SharePoint Zero-Day — 1,300+ servers still exposed 3 weeks after the patch. Is anyone else seeing exploitation artifacts in ULS logs?
Posted by Expert_Sort7434@reddit | sysadmin | View on Reddit | 17 comments
Three weeks after Microsoft patched CVE-2026-32201 — the actively exploited SharePoint spoofing zero-day from April's record Patch Tuesday — Shadowserver is still tracking 1,300+ internet-facing SharePoint servers that haven't applied the fix.
The technical root cause is CWE-20 (improper input validation) in SharePoint's request-handling pipeline. An unauthenticated attacker can send a crafted network request and have their data rendered as trusted SharePoint content to internal users — no privileges, no user interaction, low complexity.
What's catching my eye technically:
— Security researchers at Rapid7 and SecurityWeek are flagging that this is likely being chained with CVE-2026-33824 (Windows IKE RCE, CVSS 9.8) — which is pre-auth, network-reachable, and wormable in some configurations. That's a serious pivot chain.
— There's speculation CVE-2026-32201 is related to XSS (cross-site scripting) in SharePoint's page rendering engine, which would explain the integrity + confidentiality impact with no availability hit.
— The BlueHammer exploit (CVE-2026-33825, Defender PE, Volume Shadow Copy abuse) was also patched the same day — and these three together represent a multi-stage attack surface nobody is treating as a coordinated threat cluster yet.
For those running on-prem SharePoint (2016/2019/SE): Are you seeing anomalous Content-Type mismatches or encoded payloads in your ULS logs that might suggest probing or exploitation attempts? What's your detection coverage looking like?
I previously covered the Microsoft Entra ID AI Agent privilege escalation (same Patch Tuesday cycle, different product layer) here if you want the broader Microsoft enterprise attack surface context:
https://www.techgines.com/post/microsoft-entra-id-ai-agent-privilege-escalation-silverfort
Full technical breakdown of CVE-2026-32201:
https://www.techgines.com/post/cve-2026-32201-sharepoint-zero-day-spoofing
Kumorigoe@reddit
Sorry, it seems this comment or thread has violated a sub-reddit rule and has been removed by a moderator.
Do Not Conduct Marketing Operations Within This Community.
Your content may be better suited for our companion sub-reddit: /r/SysAdminBlogs
If you wish to appeal this action please don't hesitate to message the moderation team.
michivideos@reddit
I know what's sharepoint
I know what is an on-prem internet phasing server.
But what do you mean an on-prem sharepoint server?
Sounds like a on-prem OneDrive Server ....
xxbiohazrdxx@reddit
Count the em dashes
CPAtech@reddit
What's crazy is I've been using em dashes for years now I'm suspect when I reply.
discosoc@reddit
You can definitely tell who didn’t pay attention in English classes.
disclosure5@reddit
You really think people running unpatched on prem Sharepoint have the kind of detection logging your asking for (or basically any)?
TerrificVixen5693@reddit
Come on, this is just some astroturf to get us to visit their website.
Federal_Refrigerator@reddit
Yes it is and the post is written by ChatGPT 5.4, they are just begging for clicks. I think what I’m gonna do is add their domain to my pi hole blocklist tho tbh.
Carribean-Diver@reddit
Literally came here to say that the folks who are running unpatched internet facing systems are not analyzing access logs.
Burgergold@reddit
People still have Sharepoint on prem?
angrydeuce@reddit
Heh, I just permanently nuked that VM a few months ago!
Hadn't been powered on in almost 10 years lol
CantPullOutRightNow@reddit
1300 public facing.
CPAtech@reddit
If you're supporting on-prem Sharepoint these days I suspect you have bigger problems.
mrjamjams66@reddit
You know I always hated SharePoint. And then I had a client with an on-prem SharePoint (like SharePoint 2015 I think) and I learned to appreciate SharePoint online
_l33ter_@reddit
hahah 1,300+ internet-facing SharePoint --> the lacy people are the best one --> But when something does happen to them, it’s those ‘lacy’ people who are the loudest in criticising MS.
Un-fucking-belivable!
Ssakaa@reddit
yeah, the burlap people are way better. You can't trust those wool people though.
_l33ter_@reddit
hahah :D