Security Affairs
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522|Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug|Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access|Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875|Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage|Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!|CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522|Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug|Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access|Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875|Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage|Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now!|CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers|AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign|Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 106|Security Affairs newsletter Round 586 by Pierluigi Paganini – INTERNATIONAL EDITION|Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization […]

SharePoint

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code.

A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.

Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.

CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.

Organizations should apply the available security updates immediately.

watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”

Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.

In early July, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.

At the end of May, Microsoft released security updates to patch the high-severity SharePoint vulnerability CVE-2026-45659 that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a serious risk for unpatched systems. Organizations using Microsoft SharePoint should apply the updates as soon as possible.

The root cause is deserialization of untrusted data.

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Microsoft SharePoint Server flaw, tracked as CVE-2026-32201, to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-32201 (CVSS score of 6.5) is a spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS). While details are limited, it could allow attackers to view or modify exposed information. Microsoft has not disclosed how widespread exploitation is, but given the potential impact, organizations, especially those with internet-facing SharePoint servers—should prioritize testing and applying the patch quickly.

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another SharePoint issue, tracked as CVE-2026-20963, its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft)