Ethical Hacking News
Critical SharePoint RCE CVE-2026-50522 has been actively exploited despite a public proof-of-concept being released, putting on-premises Microsoft SharePoint deployments at risk. Organizations must take immediate action to patch vulnerabilities and rotate credentials to prevent unauthorized access.
The critical vulnerability CVE-2026-50522 has a CVSS score of 9.8, indicating a high risk level. Microsoft patched the issue as part of its Patch Tuesday update for July 2026, but threat actors have already exploited it. The exploitability assessment is rated "Exploitation More Likely" due to active exploitation efforts and public proof-of-concept exploits. The attack vector is Network (AV:N), with low attack complexity, making it easy for attackers to succeed. Threat actors are using this vulnerability to steal machine keys and deliver deserialization payloads. CISA has warned about exploitation of multiple SharePoint Server vulnerabilities, including CVE-2026-50522, to gain unauthorized access. Patching is not enough; defenders should rotate credentials and implement robust security measures to prevent exploitation.
The cybersecurity world has been hit with a critical vulnerability that could allow an unauthorized attacker to execute code over a network, rendering SharePoint Server versions vulnerable to deserialization of untrusted data. The vulnerability in question is CVE-2026-50522, which carries a CVSS score of 9.8. This rating places the vulnerability at a high risk level, indicating that it has a significant impact on system security.
The vulnerability was discovered by DEVCORE researcher "splitline" and reported to Microsoft, who subsequently patched the issue as part of its Patch Tuesday update for July 2026. However, despite the patch being released, threat actors have already taken advantage of the vulnerability, actively exploiting it to gain unauthorized access to on-premises instances of SharePoint Server.
The exploitability assessment for CVE-2026-50522 is rated "Exploitation More Likely," indicating that threat actors are likely to continue exploiting this vulnerability. In fact, several security vendors and organizations have reported detecting active exploitation efforts against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit.
The attack vector for CVE-2026-50522 is Network (AV:N), meaning that it can be exploited from the internet. The attack complexity is also rated as Low (AC:L), indicating that an attacker does not require significant prior knowledge of the system to achieve repeatable success with the payload against the vulnerable component.
Threat actors are using this vulnerability to steal machine keys, which allows them to maintain persistent access to the compromised systems. In some cases, threat actors are also delivering a .NET deserialization payload to a SharePoint sign-in endpoint, further highlighting the severity of the issue.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are exploiting multiple SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, to gain unauthorized access to on-premises instances.
These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities. The affected vulnerabilities allow threat actors to steal Internet Information Services (IIS) machine keys and perform deserialization techniques, further compromising the security of the systems.
In light of this critical vulnerability, it is essential for organizations that use SharePoint Server to take immediate action. Patching is not enough; defenders should rotate credentials on any assets that may have been exposed. Additionally, implementing robust security measures, such as monitoring network traffic and regularly scanning for vulnerabilities, can help prevent exploitation.
The discovery of CVE-2026-50522 highlights the importance of keeping software up-to-date and the need for organizations to stay vigilant in protecting their systems against emerging threats. By staying informed about the latest vulnerabilities and taking proactive steps to address them, organizations can minimize the risk of exploitation and ensure the security of their SharePoint Server deployments.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Vulnerability-Exposed-SharePoint-RCE-CVE-2026-50522-Under-Active-Exploitation-ehn.shtml
https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
https://nvd.nist.gov/vuln/detail/CVE-2026-50522
https://www.cvedetails.com/cve/CVE-2026-50522/
https://nvd.nist.gov/vuln/detail/CVE-2026-32201
https://www.cvedetails.com/cve/CVE-2026-32201/
https://nvd.nist.gov/vuln/detail/CVE-2026-45659
https://www.cvedetails.com/cve/CVE-2026-45659/
https://nvd.nist.gov/vuln/detail/CVE-2026-56164
https://www.cvedetails.com/cve/CVE-2026-56164/
https://nvd.nist.gov/vuln/detail/CVE-2026-58644
https://www.cvedetails.com/cve/CVE-2026-58644/
Published: Tue Jul 21 10:57:11 2026 by llama3.2 3B Q4_K_M