Microsoft SharePoint Server administrators face another urgent cybersecurity threat after security researchers confirmed that CVE-2026-50522, a critical remote code execution (RCE) vulnerability, is now being actively exploited in the wild. The attacks began shortly after a public proof-of-concept (PoC) exploit became available, highlighting the growing risks associated with delayed patching of internet-facing SharePoint environments.
The vulnerability, which Microsoft addressed during its July 2026 Patch Tuesday release, has received a CVSS score of 9.8, making it one of the most severe SharePoint security flaws disclosed this year.
Its exploitation adds to a growing list of SharePoint vulnerabilities being targeted by cybercriminals, reinforcing the need for organizations to immediately secure their on-premises SharePoint deployments.
Tracked as CVE-2026-50522, the flaw is a deserialization of untrusted data vulnerability affecting Microsoft Office SharePoint Server.
According to Microsoft, the vulnerability allows an attacker to execute arbitrary code remotely after successfully exploiting the vulnerable component. The issue was discovered and responsibly reported by DEVCORE security researcher “splitline.”
Microsoft explained that an attacker who has Site Owner-level privileges can exploit the flaw over a network to inject and execute malicious code on the SharePoint Server.
The company classified the vulnerability as having:
- Attack Vector: Network
- Attack Complexity: Low
- CVSS Score: 9.8 (Critical)
Because exploitation requires minimal complexity and can be performed remotely, Microsoft labeled the vulnerability as “Exploitation More Likely,” warning organizations that real-world attacks were expected.
Security researchers at watchTowr have now confirmed that attackers are actively exploiting CVE-2026-50522 against on-premises SharePoint environments.
According to the company, attacks accelerated soon after a public proof-of-concept exploit became available.
Researchers observed attackers stealing SharePoint machine keys using a single specially crafted request. These keys can allow attackers to maintain persistent access to compromised SharePoint servers, even after the initial vulnerability has been patched.
Because of this, security experts warn that simply installing Microsoft’s update may not be sufficient for systems that have already been compromised.
Organizations should also rotate exposed credentials and machine keys to prevent attackers from regaining access.
Security researchers from Defused Cyber have also identified exploitation attempts involving .NET deserialization payloads delivered to a SharePoint sign-in endpoint.
Interestingly, researchers observed that the malicious requests did not contain authentication information, aligning with the vulnerability’s ability to be exploited without standard authentication in certain attack scenarios.
This demonstrates how threat actors are rapidly adapting publicly available exploit techniques to compromise vulnerable SharePoint installations.
CVE-2026-50522 is now the third SharePoint Server vulnerability confirmed to be under active exploitation following Microsoft’s July 2026 security updates.
Previously exploited vulnerabilities include:
- CVE-2026-56164 – Privilege Escalation
- CVE-2026-58644 – Critical Remote Code Execution
Security researchers confirmed that both vulnerabilities had already been weaponized as zero-day attacks before Microsoft released patches.
The addition of CVE-2026-50522 significantly increases concerns that attackers are systematically targeting vulnerable SharePoint environments immediately after technical details become public.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that multiple SharePoint Server vulnerabilities are currently being exploited in real-world attacks.
According to the agency, attackers are targeting:
- CVE-2026-32201
- CVE-2026-45659
- CVE-2026-56164
- CVE-2026-58644
These vulnerabilities affect all supported on-premises SharePoint versions, including:
- SharePoint Server Subscription Edition
- SharePoint Server 2019
- SharePoint Server 2016
Threat actors are exploiting these flaws to gain unauthorized access, execute malicious code, steal Internet Information Services (IIS) machine keys, perform deserialization attacks, establish persistence, and deploy malware within enterprise environments.
Organizations operating internet-facing SharePoint servers remain at the highest risk.
Microsoft SharePoint continues to be one of the most attractive targets for cybercriminals because it stores critical business documents, sensitive corporate data, and collaboration resources.
Successful exploitation of CVE-2026-50522 could allow attackers to:
- Execute arbitrary code remotely.
- Steal SharePoint machine keys.
- Maintain long-term persistence.
- Deploy malware or ransomware.
- Escalate attacks across enterprise networks.
- Compromise sensitive business information.
With public exploit code now available, attackers can automate scanning for vulnerable SharePoint servers and launch attacks at scale.
Organizations using on-premises SharePoint Server should take immediate action to reduce their exposure.
Recommended security measures include:
- Install Microsoft’s July 2026 security updates immediately.
- Rotate SharePoint machine keys if compromise is suspected.
- Change administrator and service account credentials.
- Review SharePoint logs for suspicious requests.
- Monitor for abnormal authentication or privilege escalation events.
- Restrict internet exposure where possible.
- Deploy endpoint detection and network monitoring solutions.
Security teams should also perform incident response investigations on any systems exposed before patching, as attackers may already have established persistent access.
The active exploitation of CVE-2026-50522 demonstrates how quickly cybercriminals weaponize newly disclosed vulnerabilities once proof-of-concept exploits become public. Combined with other actively exploited SharePoint flaws, the threat landscape surrounding Microsoft’s collaboration platform continues to intensify.
For organizations relying on on-premises SharePoint, applying patches alone may not be enough. Comprehensive incident response, credential rotation, continuous monitoring, and proactive threat hunting are essential to ensure attackers have not already established a foothold.
As attacks continue to evolve, timely patch management and layered security controls remain the best defense against emerging SharePoint threats.
