Ethical Hacking News
A critical vulnerability in Microsoft SharePoint has been actively exploited following the release of a public proof-of-concept (PoC) code. The vulnerability, tracked as CVE-2026-50522, carries a CVSS score of 9.8 and allows authenticated attackers to execute arbitrary code remotely on vulnerable SharePoint servers. Organizations using Microsoft SharePoint are urged to apply the available security updates immediately to prevent long-term compromise.
CVE-2026-50522: Critical Microsoft SharePoint vulnerability with CVSS score 9.8, allowing remote code execution without authentication.Root cause: Deserialization of untrusted data, enabling attackers to execute malicious code remotely.Security experts recommend rotating machine keys and credentials to prevent long-term compromise.CISA has added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog, emphasizing the vulnerability's seriousness.Other vulnerabilities mentioned include CVE-2026-58644, CVE-2026-45659, CVE-2026-32201, and CVE-2026-20963.
CVE-2026-50522, a critical Microsoft SharePoint vulnerability, has been actively exploited following the release of a public proof-of-concept (PoC) code. The vulnerability, tracked as CVE-2026-50522, carries a CVSS score of 9.8 and allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers. Organizations using Microsoft SharePoint are urged to apply the available security updates immediately.
The root cause of this vulnerability is deserialization of untrusted data. This means that an attacker can exploit this flaw by sending malicious data to a SharePoint server, which can then be executed without any authentication or user interaction. The severity of this vulnerability lies in its potential for long-term compromise if not addressed promptly.
Security experts warn that organizations should not only apply Microsoft's updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise. Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint, with observed attacks requiring no authentication.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, highlighting the seriousness of the situation. Microsoft released security updates to patch the high-severity vulnerability CVE-2026-45659 in June 2026, which can also be exploited without authentication or user interaction.
In addition to the current critical SharePoint RCE vulnerability, there are other vulnerabilities mentioned in this context data that organizations should consider as well:
* CVE-2026-58644: A matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction and stem from the deserialization of untrusted data.
* CVE-2026-45659: A high-severity SharePoint vulnerability tracked by CISA, with a CVSS score of 8.8, which allows remote code execution.
* CVE-2026-32201: A spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS), with a CVSS score of 6.5.
* CVE-2026-20963: A deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
All these vulnerabilities highlight the importance of applying security updates and taking prompt action against potential threats. Organizations must prioritize testing and applying patches for any vulnerable systems, including SharePoint servers. By doing so, they can minimize the risk of long-term compromise and protect their sensitive information from unauthorized access.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Critical-SharePoint-Vulnerability-Exposed-A-Wake-Up-Call-for-Organizations-ehn.shtml
https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html
https://nvd.nist.gov/vuln/detail/CVE-2026-50522
https://www.cvedetails.com/cve/CVE-2026-50522/
https://nvd.nist.gov/vuln/detail/CVE-2026-45659
https://www.cvedetails.com/cve/CVE-2026-45659/
https://nvd.nist.gov/vuln/detail/CVE-2026-58644
https://www.cvedetails.com/cve/CVE-2026-58644/
https://nvd.nist.gov/vuln/detail/CVE-2026-32201
https://www.cvedetails.com/cve/CVE-2026-32201/
https://nvd.nist.gov/vuln/detail/CVE-2026-20963
https://www.cvedetails.com/cve/CVE-2026-20963/
Published: Wed Jul 22 12:32:57 2026 by llama3.2 3B Q4_K_M