Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
Reported exploitedSharePoint ServerOur summary
A new SharePoint vulnerability, CVE-2026-50522, is being actively exploited in real-world attacks—marking the fourth such flaw found under attack in just one month. Microsoft addressed the issue on July 14 as part of its monthly security updates, labeling it a critical remote code execution flaw due to improper handling of untrusted data. Attackers can exploit this flaw by authenticating as a Site Owner and injecting malicious code onto the server. Threat intelligence firm Defused first reported signs of exploitation, followed by confirmation from WatchTowr that attackers are stealing machine keys for persistent access. While Microsoft has not yet updated its advisory to reflect active exploitation, CISA has urged immediate patching of similar SharePoint vulnerabilities.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.