Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the dese

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is now under active exploitation following the public release of proof-of-concept (PoC) exploit code. The flaw, which carries a CVSS score of 9.8, was addressed by Microsoft in its July 2026 Patch Tuesday updates.
According to watchTowr researchers, active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers was observed shortly after the public exploit code became available. Attackers are reportedly leveraging the vulnerability to steal SharePoint machine keys through a single request, which could allow for persistent access even after systems are patched. Security experts are advising organizations not only to apply Microsoft's updates but also to rotate machine keys and any other potentially exposed credentials to mitigate the risk of long-term compromise.
watchTowr identified the PoC exploit code on July 20th. Within hours, their global honeypot network, Attacker Eye, detected and captured exploitation attempts utilizing this PoC that successfully compromised target systems. Cybersecurity firm Defused Cyber also reported observing threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload via a SharePoint sign-in endpoint. These observed attacks reportedly require no authentication, aligning with the vulnerability's unauthenticated remote code execution profile.
CVE-2026-50522 is a deserialization flaw that, in its initially documented form, allowed authenticated attackers with Site Owner privileges to execute arbitrary code remotely. However, subsequent analysis and observed exploitation indicate that it can be triggered without authentication or user interaction. This vulnerability is considered a matched pair with CVE-2026-58644, both stemming from the deserialization of untrusted data. CVE-2026-50522 was publicly demonstrated at Pwn2Own Berlin, where a working exploit was provided to Microsoft, yet the official advisory initially listed its exploit maturity as "unknown."
This incident follows several other SharePoint vulnerabilities that have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog this year. In early July, CISA added CVE-2026-45659, a high-severity SharePoint Server RCE flaw (CVSS 8.8) patched in May 2026, which also stemmed from deserialization of untrusted data and did not require complex conditions for exploitation.
Prior to that, in April 2026, CISA added CVE-2026-32201, a SharePoint Server spoofing vulnerability (CVSS 6.5) likely related to cross-site scripting (XSS), which could allow attackers to view or modify exposed information. In March 2026, CVE-2026-20963, another deserialization of untrusted data flaw in Microsoft Office SharePoint, was added to the KEV catalog, allowing an authorized attacker to execute code over a network.
Given the potential impact, organizations, particularly those with internet-facing SharePoint servers, are urged to prioritize testing and applying the latest security updates immediately, and to consider credential rotation for any potentially compromised assets. Microsoft has not disclosed the widespread nature of the current exploitation.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.