criticalKEV
CVE-2026-32201
SharePoint Server spoofing via improper input validation - a manipulated Referer plus a malformed query string bypasses the front-end authorization check
- Severity
- critical
- Affected product
- Microsoft SharePoint Server
- Affected versions
- Microsoft SharePoint Server all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Microsoft SharePoint Server appliance and reports this CVE when the detected version falls inside the affected range below.
July 2026 exploitation wave ('second ToolShell'). CISA confirmed active exploitation of this and the two rows below, and urged on-prem hardening. Chained to RCE, IIS machine-key theft and persistence. No `lt`: the fixed build differs per supported version and we do not track it, so this stays advisory.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →