Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 53
3 unique sources, 3 articles

Summary

Hide ▲

CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enables attackers to steal machine keys for persistence.

Related Happenings

SharePoint exploitation wave

Exploitation Wave
H score42 First: 22.07.2026 14:29 Last: 22.07.2026 14:29 Sources 1

How related: The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.

About this happening: In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
H score44 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
H score38 First: 17.03.2026 17:36 Last: 17.03.2026 17:36 Sources 1

About this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...

UnsolicitedBooker Central Asian telecom phishing campaign

Campaign
H score31 First: 24.02.2026 11:54 Last: 24.02.2026 11:54 Sources 1

About this happening: The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...

Timeline

  1. 22.07.2026 03:00 1 articles · 13d ago

    Microsoft patches critical SharePoint Server RCE CVE-2026-50522

    Mitigation Patch Update

    Microsoft fixed CVE-2026-50522 in its July 14 Patch Tuesday updates. Microsoft describes the SharePoint Server flaw as a critical remote code execution vulnerability stemming from deserialization of untrusted data, and says an attacker authenticated as at least a Site Owner could write arbitrary code and execute it remotely.

    Show sources
  2. 22.07.2026 03:00 2 articles · 13d ago

    WatchTowr confirms active exploitation of CVE-2026-50522

    Exploitation Observed

    WatchTowr confirmed active exploitation shortly after PoC exploit code was released and said attackers were pulling SharePoint machine keys via a single request to retain long-term access. Defused had earlier reported honeypot exploitation attempts against what appeared to be a zero-day SharePoint vulnerability and later tied the target to CVE-2026-50522.

    Show sources
  3. 21.07.2026 23:06 1 articles · 13d ago

    Microsoft SharePoint deserialization RCE (CVE-2026-50522)

    Initial Disclosure

    CVE-2026-50522 emerged as a Microsoft SharePoint deserialization flaw with remote-code-execution potential, and Microsoft had already shipped July security updates for it. Public proof-of-concept code quickly made exploitation practical against on-premise servers.

    Show sources
  4. 21.07.2026 17:57 3 articles · 13d ago

    watchTowr reports active exploitation of CVE-2026-50522 in SharePoint Server

    Initial Disclosure

    Microsoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday update, and watchTowr said it detected active exploitation against on-premises Microsoft SharePoint deployments after a public proof-of-concept exploit. The flaw is a critical deserialization issue in Microsoft Office SharePoint that can allow remote code execution, and attackers are said to be stealing machine keys to maintain persistent access; CISA also warned that multiple SharePoint Server vulnerabilities are being exploited to gain unauthorized access to on-premises instances.

    Show sources