A critical remote code execution vulnerability in Microsoft Office SharePoint, identified as CVE-2026-50522, is being actively exploited by attackers, posing a significant threat to organizations using the platform. This deserialization of untrusted data flaw, which has a CVSS score of 9.8, can be leveraged by unauthorized users to execute malicious code over a network. Microsoft addressed this issue as part of its July 2026 Patch Tuesday update, with credits given to DEVCORE for discovering the vulnerability. The fact that a proof-of-concept has been made public1 has likely accelerated the exploitation efforts. Given the severity of this vulnerability and its active exploitation, it is crucial for organizations to prioritize patching their SharePoint systems to prevent potential breaches. The exploitation status of CVE-2026-50522 underscores the need for prompt action to mitigate the risk of remote code execution attacks.
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
⚠️ Critical Alert
Why This Matters
CVE-2026-50522 is in active discussion involving Microsoft — exploitation status determines whether this is patch-now or monitor.
References
- The Hacker News. (2026, July 21). Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC. *The Hacker News*. https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
Original Source
The Hacker News
Read original →