Skip to main content

SharePoint Server vulnerabilities

3 published alerts for Microsoft SharePoint Server.

Actively exploited (KEV)

CVE-2026-32201

Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-32201). Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. CISA remediation due date: 2026-04-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-24955

Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-24955). Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. CISA remediation due date: 2024-04-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-29357

Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-29357). Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. CISA remediation due date: 2024-01-31. If you need help checking exposure, call (864) 335-9223.