Collab365 SpacesCollab365 Spaces
SpacesBoardsPricingAcademy membersHow It Works
Collab365 Spaces

AI changes work. Know what to do.

Follow Collab365

FacebookLinkedInInstagramX (Twitter)TikTokYouTube
Excellent on TrustpilotTrustScore 4.5/514 reviews

Platform

  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams

Company

  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Cookie Policy
Platform
  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams
Company
  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact
Legal
  • Privacy
  • Terms
  • Cookie Policy

© 2026 Collab365 Spaces Limited. All rights reserved.

Badhan Ct, Castle St, Hadley, Telford, Shropshire, TF1 5QX, UK

AI changes work. Know what to do.
See what is included

Microsoft patches actively exploited zero-day flaw in SharePoint Server

Updated20 Apr20 Apr 2026
Microsoft patches actively exploited zero-day flaw in SharePoint Server

Microsoft has released its April 2026 Patch Tuesday update to address 165 vulnerabilities across its product suite. The release includes an urgent fix for CVE-2026-32201, an actively exploited zero-day flaw in SharePoint Server. The vulnerability carries a severity score of 6.5 and allows attackers to bypass authentication on internet-facing servers. This cross-site scripting failure enables hackers to inject malicious scripts and execute JavaScript directly in a user browser for session hijacking or phishing. The US Cybersecurity and Infrastructure Security Agency has added the flaw to its known exploited vulnerabilities catalog. Federal agencies have until April 28 to apply the patch.

IT teams migrating to Microsoft 365 often leave legacy on-premises SharePoint servers running to host old archives or custom applications. Because these servers sit quietly in the background and require no active maintenance, administrators frequently exclude them from routine security audits and patch cycles. This zero-day turns those forgotten servers into immediate liabilities. Attackers are actively scanning for unpatched internet-facing SharePoint instances to hijack user sessions and deploy ransomware. A single unpatched legacy server can now compromise credentials that grant access to your modern cloud environment.

Analysis

Do not assume you are safe just because your primary intranet lives in SharePoint Online. Check your infrastructure today for any lingering on-premises SharePoint servers you kept alive for legacy file archives. If you find one, patch it immediately or disconnect it from the internet entirely.

Read full story on computerweekly.com

Source note

Source note

Pulse published by Collab365 Spaces. Cite as "Microsoft patches actively exploited zero-day flaw in SharePoint Server", Collab365 Spaces.

spaces.collab365.com/posts/microsoft-patches-actively-exploited-zero-day-flaw-fBhHH5