A critical vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is being actively exploited after a public proof-of-concept (PoC) code was released, allowing authenticated attackers to execute arbitrary code remotely on vulnerable servers1. This deserialization flaw, which has a CVSS score of 9.8, was patched in Microsoft's July 2026 Patch Tuesday, but the release of the PoC code has triggered active exploitation. The vulnerability can be exploited by attackers with Site Owner privileges, making it a significant concern for organizations using SharePoint. The fact that a PoC code is publicly available increases the likelihood of widespread exploitation, making prompt patching essential. So what matters to practitioners is that the active exploitation status of CVE-2026-50522 dictates whether this is a patch-now or monitor situation, highlighting the need for immediate attention to prevent potential breaches.
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
⚠️ Critical Alert
Why This Matters
CVE-2026-50522 is in active discussion involving Microsoft — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, July 21). Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522. *SecurityAffairs*. https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html
Original Source
SecurityAffairs
Read original →