LIVE · cybersecurity feed
Live wire
CVE-2026-50522critical

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the dese

zeroday.news · 11d ago

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is now under active exploitation following the public release of proof-of-concept (PoC) exploit code. The flaw, which carries a CVSS score of 9.8, was addressed by Microsoft in its July 2026 Patch Tuesday updates.

According to watchTowr researchers, active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers was observed shortly after the public exploit code became available. Attackers are reportedly leveraging the vulnerability to steal SharePoint machine keys through a single request, which could allow for persistent access even after systems are patched. Security experts are advising organizations not only to apply Microsoft's updates but also to rotate machine keys and any other potentially exposed credentials to mitigate the risk of long-term compromise.

watchTowr identified the PoC exploit code on July 20th. Within hours, their global honeypot network, Attacker Eye, detected and captured exploitation attempts utilizing this PoC that successfully compromised target systems. Cybersecurity firm Defused Cyber also reported observing threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload via a SharePoint sign-in endpoint. These observed attacks reportedly require no authentication, aligning with the vulnerability's unauthenticated remote code execution profile.

CVE-2026-50522 is a deserialization flaw that, in its initially documented form, allowed authenticated attackers with Site Owner privileges to execute arbitrary code remotely. However, subsequent analysis and observed exploitation indicate that it can be triggered without authentication or user interaction. This vulnerability is considered a matched pair with CVE-2026-58644, both stemming from the deserialization of untrusted data. CVE-2026-50522 was publicly demonstrated at Pwn2Own Berlin, where a working exploit was provided to Microsoft, yet the official advisory initially listed its exploit maturity as "unknown."

This incident follows several other SharePoint vulnerabilities that have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog this year. In early July, CISA added CVE-2026-45659, a high-severity SharePoint Server RCE flaw (CVSS 8.8) patched in May 2026, which also stemmed from deserialization of untrusted data and did not require complex conditions for exploitation.

Prior to that, in April 2026, CISA added CVE-2026-32201, a SharePoint Server spoofing vulnerability (CVSS 6.5) likely related to cross-site scripting (XSS), which could allow attackers to view or modify exposed information. In March 2026, CVE-2026-20963, another deserialization of untrusted data flaw in Microsoft Office SharePoint, was added to the KEV catalog, allowing an authorized attacker to execute code over a network.

Given the potential impact, organizations, particularly those with internet-facing SharePoint servers, are urged to prioritize testing and applying the latest security updates immediately, and to consider credential rotation for any potentially compromised assets. Microsoft has not disclosed the widespread nature of the current exploitation.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]

breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.