Skip to content
CC-4770

CC-4770

Digital.Nhs.Uk [email protected] (NHS Digital) April 15, 2026

Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server

Scheduled updates for Microsoft products address 165 vulnerabilities, including CVE‑2026‑32201, an exploited spoofing vulnerability affecting SharePoint Server

The following platforms are known to be affected:

Microsoft SharePoint Server

The following platforms are also known to be affected:

Multiple other Microsoft platforms. Please see Microsoft's April 2026 Security Update guide for full details.

Exploitation of CVE-2026-32201

Microsoft states that exploitation of CVE‑2026‑32201 has been detected. NHS England National CSOC assesses future exploitation as highly likely.

Microsoft has released security updates to address 165 vulnerabilities in Microsoft products, including CVE-2026-32201, an exploited vulnerability that could allow an unauthorised attacker to perform spoofing over a network.

Windows Autopatch is enabling hotpatch security updates by default

Starting with the May 2026 Windows security update, Microsoft will be enabling hotpatch security updates by default for devices. This change will impact all eligible devices managed by Microsoft Intune, and applies whether you use Windows Autopatch through Microsoft Intune or the Windows updates API in Microsoft Graph.

For more details, please see Microsoft's blog post.

Affected organisations are encouraged to review Microsoft's April 2026 Security Updates and apply the relevant updates as soon as possible.

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Last edited: 15 April 2026 3:48 pm