Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s April 2026 Patch Tuesday release included a SharePoint Server zero-day, CVE-2026-32201, that was reported as exploited in the wild. SecurityWeek counted 165 vulnerabilities fixed across the release on April 14, 2026; its headline’s “160 other” is not a separate total.

For administrators, the immediate task is to confirm whether the affected SharePoint Server deployment is in scope and install the update Microsoft lists for that environment. The available reporting does not establish affected builds or package numbers, so use Microsoft’s live update record rather than guessing.

What happened in Microsoft’s April 2026 Patch Tuesday release?

SecurityWeek reported 165 vulnerabilities fixed in Microsoft’s April 2026 release. The report’s headline refers to the SharePoint zero-day and “160 other” vulnerabilities, while its stated release-wide count is 165. Treat 165 as SecurityWeek’s count for that specific release, not as a current cumulative total. SecurityWeek’s April 14, 2026 report is the source for that figure.

The headline issue was CVE-2026-32201, a SharePoint Server spoofing vulnerability. Microsoft rated it Important with a CVSS score of 6.5, as reported by SecurityWeek. The report said the flaw was being exploited in the wild. It did not identify an attacker or motive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What is CVE-2026-32201?

SecurityWeek described CVE-2026-32201 as an improper-input-validation flaw that an unauthorized attacker could exploit over a network to perform spoofing. The article reproduced Microsoft’s description: “Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.” It also said Microsoft noted exploitation could allow access to sensitive information and alteration of that information. This wording is Microsoft’s description as quoted by SecurityWeek, not an independently verified quotation from the opened CVE record. Read SecurityWeek’s account.

“Exploited in the wild” means the report identified real-world exploitation; it does not establish who carried it out, how many organizations were affected, or the attacker’s purpose. Those details were not established in the reporting.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How should administrators prioritize this update?

Prioritize confirmed exploitation separately from Microsoft’s severity label and from predictive exploitation assessments. SecurityWeek said 19 other vulnerabilities in the April release were rated “exploitation more likely.” That rating is not equivalent to confirmation that those flaws were already being exploited.

  • Confirmed exploitation: CVE-2026-32201 was reported as exploited in the wild, making prompt applicability checks and remediation important.
  • Severity: SecurityWeek reported Microsoft’s Important rating and CVSS 6.5 score for CVE-2026-32201.
  • Likelihood assessments: The report’s 19 “exploitation more likely” vulnerabilities are a distinct group; do not describe them as confirmed zero-days.
  • Exposure and applicability: Determine whether your SharePoint Server deployment is affected and which update applies by consulting Microsoft’s current record.

How to check applicability and install the right fix

  1. Open Microsoft’s Security Update Guide and search for CVE-2026-32201.
  2. Check Microsoft’s current CVE record for affected products, applicable builds, and remediation instructions: CVE-2026-32201.
  3. Match the listed affected product and update to the SharePoint Server version and build in your environment. Do not infer a package number or fixed build from the CVE identifier alone.
  4. Apply the Microsoft update that matches the deployment, following the instructions and prerequisites Microsoft provides for that update.
  5. After installation, verify the installed build against Microsoft’s stated fixed version and document the result in your organization’s patch process.

The exact affected builds and update package numbers are not specified in the reporting cited here. Microsoft’s live record is the appropriate place to establish those details before deploying a fix.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What did CISA’s KEV listing and deadline mean?

SecurityWeek reported that CVE-2026-32201 was added to CISA’s Known Exploited Vulnerabilities catalog and that federal agencies had an April 28, 2026 remediation deadline. That deadline is historical and has passed; it is not a future due date for organizations reading this article. The report’s deadline applies to federal remediation requirements, not a universal deadline for every organization. CISA’s KEV catalog provides the catalog context.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does this apply to SharePoint Online?

The available reporting identifies the issue as a SharePoint Server vulnerability, but it does not establish exact affected product versions or resolve whether SharePoint Online is affected. Check Microsoft’s current CVE and update records for product scope rather than assuming that on-premises SharePoint guidance applies to Microsoft-hosted services.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Microsoft’s July 2025 SharePoint incident guidance concerns different vulnerabilities. It says those 2025 issues affected on-premises SharePoint Server, but it is not evidence of the product scope for CVE-2026-32201. Microsoft’s July 2025 guidance should be read in the context of those separate CVEs.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.