Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild
ID: 44e2c8bf-7142-5c5c-a6c1-7c72895e50d4
STIX ID: report--44e2c8bf-7142-5c5c-a6c1-7c72895e50d4
Feed Name: cybersecurityNews.com
A critical unauthenticated .NET deserialization RCE (CVE-2026-50522, CVSS 9.8) affects on‑prem SharePoint Server 2016/2019/Subscription Edition and can enable full server takeover; Microsoft issued July 2026 patches (published alongside CVE-2026-58644), defenders are urged to apply updates immediately, restrict internet exposure, and monitor for unauthenticated deserialization payloads as honeypot and telemetry data plus an elevated EPSS indicate meaningful near-term exploitation risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
