Active exploit on SharePoint CVE-2026-50522 after Patch Tuesday
Microsoft SharePoint has come under attack following the publication of a public proof-of-concept for CVE-2026-50522, a critical deserialization flaw that can lead to remote code execution. Researchers at watchTowr and other analysts have observed that the exploit was quickly turned into real-world attacks against exposed instances. The issue is particularly serious because attackers can use it to gain initial access and then steal machine keys, paving the way for deeper compromises. Microsoft had already fixed the bug in the July 2026 Patch Tuesday, but the speed with which it moved from patch to offensive use shows how short the defense window is. For organizations using SharePoint, this means immediately verifying the update, looking for indicators of compromise, and assuming that unpatched instances are already at concrete risk.
Sources
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — The Hacker News
- Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 — Security Affairs


Leave a Reply