Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Reported exploitedSharePoint ServerOur summary
Microsoft has confirmed that a critical vulnerability in SharePoint Server, CVE-2026-50522, is currently being actively exploited. This flaw allows unauthenticated attackers to execute arbitrary code remotely through deserialization of untrusted data. A proof-of-concept (PoC) exploit was recently made public, enabling threat actors to extract SharePoint machine keys and maintain persistent access. The vulnerability affects all supported on-premises versions of SharePoint Server and carries a CVSS score of 9.8. Security experts warn that patching alone is insufficient—defenders should also rotate credentials for potentially compromised systems.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.