Home / Jul 23, 2026 / Story
0
#3 The Hacker News general July 21, 2026 at 14:57 UTC

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

By [email protected] (The Hacker News)

AI Summary

CVE-2026-50522, a critical (CVSS 9.8) deserialization vulnerability in Microsoft SharePoint Server, is under active exploitation following public PoC release, marking the fourth SharePoint flaw exploited in a single month's wave of attacks. Threat actors are leveraging it to steal machine keys and maintain persistent access. Security teams running SharePoint should treat this as an emergency patch priority given the July 2026 Patch Tuesday fix and rapid weaponization timeline.

Relevance score: 90.0/100

# More from July 23