Tag

Deserialization

All articles tagged with #deserialization

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522
security2 hours ago

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522

Microsoft patched CVE-2026-50522, a critical deserialization-based RCE in SharePoint Server, but a public PoC and threat intel indicate active exploitation of on‑prem deployments. The flaw allows remote code execution over the network, potentially by an attacker authenticated as a Site Owner, enabling arbitrary code execution and theft of IIS machine keys for persistence. Defenders should rotate credentials and deploy patches; CISA warns that multiple SharePoint vulnerabilities are being exploited across supported on‑premises versions.