Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Key Points:
- Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, with a CVSS score of 9.8, which allows unauthorized remote code execution via deserialization of untrusted data; this flaw is actively exploited in the wild.
- The vulnerability can be exploited by an attacker with at least Site Owner privileges to inject and execute arbitrary code remotely on SharePoint Servers, with low attack complexity and network-based attack vector.
- Security researchers and vendors, including watchTowr and Defused Cyber, have observed active exploitation involving theft of SharePoint machine keys to maintain persistent access, often without requiring authentication.
- CVE-2026-50522 is the third actively exploited SharePoint Server flaw patched in July 2026, following two other critical zero-day vulnerabilities, highlighting ongoing targeted attacks against on-premises SharePoint deployments.
- The U.S. CISA has issued warnings about multiple SharePoint Server vulnerabilities being exploited for remote code execution and post-exploitation activities, affecting all supported on-premises SharePoint versions and urging organizations to apply patches and rotate credentials.