SharePoint RCE under active exploitation
ID: 9e93728d-dbac-5906-9c7e-e86795f8181a
STIX ID: report--9e93728d-dbac-5906-9c7e-e86795f8181a
Feed Name: ThreatLocker Blog
This report describes two critical deserialization vulnerabilities in on-premises Microsoft SharePoint (CVE-2026-50522 and CVE-2026-58644) that can lead to remote code execution and other severe impacts (webshells, credential theft, persistence). CVE-2026-50522 has a 9.8 severity and is reported as under active exploitation; affected SharePoint Server versions and build numbers are listed along with available cumulative updates and mitigation recommendations (apply patches immediately and restrict access to approved devices).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
