Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enables attackers to steal machine keys for persistence.
Related Happenings
SharePoint exploitation wave
Exploitation Wave
H score42
First: 22.07.2026 14:29
Last: 22.07.2026 14:29
Sources 1
How related:
The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.
About this happening:
In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.
SharePoint exploitation wave
Exploitation WaveHow related: The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.
About this happening: In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Warlock ransomware post-exploitation tooling upgrades
Malware Activity
H score38
First: 17.03.2026 17:36
Last: 17.03.2026 17:36
Sources 1
About this happening:
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Warlock ransomware post-exploitation tooling upgrades
Malware ActivityAbout this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
UnsolicitedBooker Central Asian telecom phishing campaign
Campaign
H score31
First: 24.02.2026 11:54
Last: 24.02.2026 11:54
Sources 1
About this happening:
The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
UnsolicitedBooker Central Asian telecom phishing campaign
CampaignAbout this happening: The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
Timeline
-
22.07.2026 03:00 1 articles · 13d ago
Microsoft patches critical SharePoint Server RCE CVE-2026-50522
Mitigation Patch UpdateMicrosoft fixed CVE-2026-50522 in its July 14 Patch Tuesday updates. Microsoft describes the SharePoint Server flaw as a critical remote code execution vulnerability stemming from deserialization of untrusted data, and says an attacker authenticated as at least a Site Owner could write arbitrary code and execute it remotely.
Show sources
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks — www.securityweek.com — 22.07.2026 14:29
-
22.07.2026 03:00 2 articles · 13d ago
WatchTowr confirms active exploitation of CVE-2026-50522
Exploitation ObservedWatchTowr confirmed active exploitation shortly after PoC exploit code was released and said attackers were pulling SharePoint machine keys via a single request to retain long-term access. Defused had earlier reported honeypot exploitation attempts against what appeared to be a zero-day SharePoint vulnerability and later tied the target to CVE-2026-50522.
Show sources
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks — www.securityweek.com — 22.07.2026 14:29
- Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks — www.securityweek.com — 22.07.2026 14:29
-
21.07.2026 23:06 1 articles · 13d ago
Microsoft SharePoint deserialization RCE (CVE-2026-50522)
Initial DisclosureCVE-2026-50522 emerged as a Microsoft SharePoint deserialization flaw with remote-code-execution potential, and Microsoft had already shipped July security updates for it. Public proof-of-concept code quickly made exploitation practical against on-premise servers.
Show sources
- Critical SharePoint RCE flaw exploited to steal machine keys — www.bleepingcomputer.com — 21.07.2026 23:06
-
21.07.2026 17:57 3 articles · 13d ago
watchTowr reports active exploitation of CVE-2026-50522 in SharePoint Server
Initial DisclosureMicrosoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday update, and watchTowr said it detected active exploitation against on-premises Microsoft SharePoint deployments after a public proof-of-concept exploit. The flaw is a critical deserialization issue in Microsoft Office SharePoint that can allow remote code execution, and attackers are said to be stealing machine keys to maintain persistent access; CISA also warned that multiple SharePoint Server vulnerabilities are being exploited to gain unauthorized access to on-premises instances.
Show sources
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — thehackernews.com — 21.07.2026 17:57
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — thehackernews.com — 21.07.2026 17:57
- Critical SharePoint RCE flaw exploited to steal machine keys — www.bleepingcomputer.com — 21.07.2026 23:06