256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC - The Hacker News

Share
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC - The Hacker News
Image · Internet

What the report says

The Hacker News reported on July 21, 2026, that CVE-2026-50522, a critical Microsoft SharePoint Server remote code execution vulnerability, is being actively exploited after the release of a public proof-of-concept exploit. The report cited security firm watchTowr, which said attackers are targeting on-premises SharePoint deployments and extracting machine keys that could help them retain access.

Microsoft addressed the flaw in its July 2026 Patch Tuesday updates and rated it 9.8 on the CVSS severity scale. The company described the issue as unsafe deserialization in Microsoft Office SharePoint that could let an attacker run code over a network. Microsoft credited DEVCORE researcher “splitline” for discovering and reporting the vulnerability, and assessed exploitation as more likely.

There is some ambiguity in the public details: Microsoft’s advisory language cited in the article refers to an attacker authenticated at least as a Site Owner, while Defused Cyber reportedly observed requests without authentication material and linked them to the same flaw. Defused Cyber also said threat actors appear to be sending .NET deserialization payloads to a SharePoint sign-in endpoint.

The development matters because SharePoint is widely used in enterprise environments and on-premises servers often hold sensitive internal data. The Hacker News noted that CVE-2026-50522 is the third SharePoint Server vulnerability patched in July 2026 to face exploitation, alongside CVE-2026-56164 and CVE-2026-58644. CISA has separately warned that multiple SharePoint flaws are being used to gain unauthorized access, steal IIS machine keys, establish persistence and deploy malware. watchTowr advised that patching alone may not be sufficient and that exposed credentials or keys should be rotated.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting