Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
ID: 393e9ff4-d160-521a-a755-c68b4f46ace3
STIX ID: report--393e9ff4-d160-521a-a755-c68b4f46ace3
Feed Name: Security Affairs
Threat Score
A critical SharePoint deserialization vulnerability (CVE-2026-50522, CVSS 9.8) with publicly released PoC is being actively exploited to achieve unauthenticated remote code execution and steal SharePoint machine keys, enabling persistent access; organizations are advised to apply Microsoft patches immediately and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
