Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522

1 min read
Source: The Hacker News
Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522
Photo: The Hacker News
TL;DR Summary

Microsoft patched CVE-2026-50522, a critical deserialization-based RCE in SharePoint Server, but a public PoC and threat intel indicate active exploitation of on‑prem deployments. The flaw allows remote code execution over the network, potentially by an attacker authenticated as a Site Owner, enabling arbitrary code execution and theft of IIS machine keys for persistence. Defenders should rotate credentials and deploy patches; CISA warns that multiple SharePoint vulnerabilities are being exploited across supported on‑premises versions.

Share this article

Reading Insights

Total Reads

0

Unique Readers

5

Time Saved

2 min

vs 3 min read

Condensed

82%

40773 words

Want the full story? Read the original article

Read on The Hacker News