CVE Tools

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

The Hacker NewsBy The Hacker News

Reported exploitedSharePoint Server

Our summary

Microsoft has confirmed that a critical vulnerability in SharePoint Server, CVE-2026-50522, is currently being actively exploited. This flaw allows unauthenticated attackers to execute arbitrary code remotely through deserialization of untrusted data. A proof-of-concept (PoC) exploit was recently made public, enabling threat actors to extract SharePoint machine keys and maintain persistent access. The vulnerability affects all supported on-premises versions of SharePoint Server and carries a CVSS score of 9.8. Security experts warn that patching alone is insufficient—defenders should also rotate credentials for potentially compromised systems.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store