Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522

TL;DR Summary
Microsoft patched CVE-2026-50522, a critical deserialization-based RCE in SharePoint Server, but a public PoC and threat intel indicate active exploitation of on‑prem deployments. The flaw allows remote code execution over the network, potentially by an attacker authenticated as a Site Owner, enabling arbitrary code execution and theft of IIS machine keys for persistence. Defenders should rotate credentials and deploy patches; CISA warns that multiple SharePoint vulnerabilities are being exploited across supported on‑premises versions.
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC The Hacker News
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED) Rapid7
- CISA sounds alarm over trio of exploited SharePoint flaws The Register
- CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities SecurityWeek
- Microsoft SharePoint under attack via new exploit Cybersecurity Dive
Reading Insights
Total Reads
0
Unique Readers
5
Time Saved
2 min
vs 3 min read
Condensed
82%
407 → 73 words
Want the full story? Read the original article
Read on The Hacker News