Home/News/SharePoint RCE CVE-2026-50522 Exploited After PoC
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SharePoint RCE CVE-2026-50522 Exploited After PoC

SharePoint RCE CVE-2026-50522 Exploited After PoC

A critical vulnerability in Microsoft Office SharePoint, designated CVE-2026-50522, is currently under active exploitation, according to a July 2026 report by watchTowr. This flaw, which carries a CVSS score of 9.8, involves the deserialization of untrusted data within SharePoint Server. Its exploitation could enable an unauthorized attacker to execute arbitrary code remotely over a network, posing a significant security risk.

Microsoft addressed this vulnerability as part of its July 2026 Patch Tuesday updates, releasing a fix to mitigate the threat. The company credited DEVCORE for discovering and reporting the vulnerability, highlighting the collaborative effort in identifying and addressing such critical security issues. The disclosure of a public proof-of-concept (PoC) shortly after the patch release appears to have accelerated its exploitation by malicious actors.

The vulnerability's critical nature stems from its potential to grant attackers full control over affected SharePoint servers. This could lead to widespread data breaches, system compromise, and further network infiltration. Organizations utilizing Microsoft Office SharePoint are strongly advised to apply the latest security patches released by Microsoft immediately to protect their environments from this actively exploited threat. The rapid exploitation underscores the importance of timely patch management and proactive security monitoring.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next