logo

Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

ID: 44e2c8bf-7142-5c5c-a6c1-7c72895e50d4

STIX ID: report--44e2c8bf-7142-5c5c-a6c1-7c72895e50d4

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Guru Baran

...
...

A critical unauthenticated .NET deserialization RCE (CVE-2026-50522, CVSS 9.8) affects on‑prem SharePoint Server 2016/2019/Subscription Edition and can enable full server takeover; Microsoft issued July 2026 patches (published alongside CVE-2026-58644), defenders are urged to apply updates immediately, restrict internet exposure, and monitor for unauthenticated deserialization payloads as honeypot and telemetry data plus an elevated EPSS indicate meaningful near-term exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.