logo

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

ID: 393e9ff4-d160-521a-a755-c68b4f46ace3

STIX ID: report--393e9ff4-d160-521a-a755-c68b4f46ace3

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Pierluigi Paganini

...
...

A critical SharePoint deserialization vulnerability (CVE-2026-50522, CVSS 9.8) with publicly released PoC is being actively exploited to achieve unauthenticated remote code execution and steal SharePoint machine keys, enabling persistent access; organizations are advised to apply Microsoft patches immediately and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.