The point: A critical SharePoint RCE (CVE-2026-50522, CVSS 9.8) is being actively exploited following public release of a proof-of-concept.
The critical SharePoint security vulnerability CVE-2026-50522 (CVSS 9.8) is being actively exploited following the publication of a proof-of-concept. The vulnerability allows attackers to achieve remote code execution through insecure deserialization of data.
Microsoft patched the security vulnerability CVE-2026-50522 in July 2026 as part of its monthly Patch Tuesday. Following the now publicly available proof-of-concept, security firm watchTowr reports active exploitation of the vulnerability in the wild.
CVE-2026-50522 is a flaw in the deserialization of untrusted data in Microsoft Office SharePoint. The high CVSS score of 9.8 reflects that an unauthenticated attacker can execute code remotely over a network with minimal complexity. Microsoft credited security firm DEVCORE for reporting the vulnerability.
This is already the third critical SharePoint vulnerability addressed in the July update. The rapid transition from patch release to active exploitation following PoC publication underscores the heightened attack risk for systems that remain unpatched.
Source: thehackernews.com · Published 21 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.