Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
ID: 163c8739-fba2-53f7-933e-c06339a2f2e3
STIX ID: report--163c8739-fba2-53f7-933e-c06339a2f2e3
Feed Name: The Hacker News
Microsoft patched CVE-2026-50522, a critical (CVSS 9.8) deserialization flaw in SharePoint Server that is being actively exploited in the wild to achieve remote code execution and to steal machine/IIS keys; public proof-of-concept code and vendor telemetry (watchTowr, Defused Cyber) indicate unauthenticated requests are being used to pull keys, and CISA warns multiple SharePoint vulnerabilities are being used against on-prem deployments — patching and credential rotation are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
