Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server
Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server
The following platforms are known to be affected:
The following platforms are also known to be affected:
Multiple other Microsoft platforms. Please see Microsoft's April 2026 Security Update guide for full details.
Exploitation of CVE-2026-32201
Microsoft states that exploitation of CVE‑2026‑32201 has been detected. NHS England National CSOC assesses future exploitation as highly likely.
Microsoft has released security updates to address 165 vulnerabilities in Microsoft products, including CVE-2026-32201, an exploited vulnerability that could allow an unauthorised attacker to perform spoofing over a network.
Windows Autopatch is enabling hotpatch security updates by default
Starting with the May 2026 Windows security update, Microsoft will be enabling hotpatch security updates by default for devices. This change will impact all eligible devices managed by Microsoft Intune, and applies whether you use Windows Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph.
For more details, please see Microsoft's blog post.
Affected organisations are encouraged to review Microsoft's April 2026 Security Updates and apply the relevant updates as soon as possible.
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Last edited: 15 April 2026 3:48 pm
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
