logo

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

ID: 163c8739-fba2-53f7-933e-c06339a2f2e3

STIX ID: report--163c8739-fba2-53f7-933e-c06339a2f2e3

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Microsoft patched CVE-2026-50522, a critical (CVSS 9.8) deserialization flaw in SharePoint Server that is being actively exploited in the wild to achieve remote code execution and to steal machine/IIS keys; public proof-of-concept code and vendor telemetry (watchTowr, Defused Cyber) indicate unauthenticated requests are being used to pull keys, and CISA warns multiple SharePoint vulnerabilities are being used against on-prem deployments — patching and credential rotation are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.