Critical

SharePoint, Microsoft, RCE, deserialization, CVE-2026-50522, active exploitation, Patch Tuesday

SharePoint CVE-2026-50522: Public PoC, Active RCE

SharePoint CVE-2026-50522 (CVSS 9.8) is under active RCE exploitation after a public PoC, EPSS now 99.5th percentile. Affected versions and fixes.

SharePoint CVE-2026-50522: Public PoC Drives Active RCE Exploitation

SharePoint CVE-2026-50522, a critical CVSS 9.8 remote code execution flaw in on-premises SharePoint Server, is under active exploitation after a public proof-of-concept (PoC) was released, according to watchTowr. It is a deserialization bug that lets an unauthenticated attacker run code over the network, and it is the third SharePoint flaw from Microsoft's July 2026 Patch Tuesday to come under attack. Its EPSS score has since climbed to the 99.5th percentile. Patch on-premises SharePoint Server now, and rotate machine keys after.

Threat actors are exploiting CVE-2026-50522, a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint that allows unauthenticated network code execution. watchTowr reported in-the-wild exploitation after a public PoC lowered the barrier to entry, continuing a familiar pattern in which on-premises SharePoint is rapidly weaponized once technical details circulate. Because the flaw is a deserialization bug, a single crafted request can lead directly to code execution on the server.

Is there a public PoC for CVE-2026-50522, and is it being exploited?

Yes on both counts, and the two are linked. A public proof-of-concept exploit is what turned this from a theoretical patch item into active in-the-wild attacks: watchTowr observed exploitation after the PoC circulated, which is the moment the exposure window effectively closed. That shift shows up in the data. At disclosure the flaw's EPSS score sat around the 97th percentile; it has since risen to the 99.5th percentile, roughly a 77% modeled probability of exploitation, among the highest ratings the system produces. When a public PoC exists for an unauthenticated RCE, treat exploitation as ongoing rather than possible.

How severe is SharePoint CVE-2026-50522?

It is critical by every measure that matters. The CVSS 3.1 base score is 9.8 with the vector AV:N/AC:L/PR:N/UI:N: network-reachable, low complexity, and requiring neither privileges nor user interaction. Combined with a 99.5th-percentile EPSS and confirmed exploitation, this is the profile of a flaw that belongs at the very top of the patch queue for anyone running SharePoint on-premises.

Which SharePoint versions are affected?

Product

Status

SharePoint Server (on-premises)

Affected, patch via July 2026 update

SharePoint Subscription Edition / 2019 / 2016 (on-prem)

Affected, apply the July 2026 security update

SharePoint Online (Microsoft 365)

Not affected (cloud-managed)

Microsoft addressed the flaw in its July 2026 Patch Tuesday release, and on-premises administrators must apply the update themselves. SharePoint Online tenants are managed by Microsoft and are not affected by this on-prem flaw.

What should defenders do now?

Patching is necessary but not sufficient for a deserialization bug, because these exploits frequently abuse stolen cryptographic keys, and patching alone does not evict an attacker who already has them. Work through this order:

  • Apply the July 2026 SharePoint Server security update for CVE-2026-50522 on every on-prem farm.

  • Rotate SharePoint machine keys (the ASP.NET ValidationKey and DecryptionKey) after patching, so a previously stolen key cannot be replayed.

  • Hunt for web shells in the SharePoint LAYOUTS directories and for unexpected w3wp.exe child processes.

  • Restrict internet exposure of SharePoint admin and web endpoints wherever business needs allow.

Our read

SharePoint has become a reliable re-run: a public PoC lands, and on-premises servers are exploited within days. CVE-2026-50522 sitting in the 99.5th EPSS percentile, as the third flaw from a single Patch Tuesday to be attacked, tells you the exposure window is measured in days, not quarters. Our 2025 KEV analysis found the median gap from disclosure to exploitation was 26 days, and 20% of flaws were exploited on or before disclosure day. For an internet-reachable RCE with a public exploit already circulating, "we'll patch at month-end" is the vulnerability. Continuously verifying that every farm is patched, and that keys were rotated after, is the control that actually closes it.

Reporting by The Hacker News; exploitation detail per watchTowr. CVSS, EPSS, and CWE per NVD and FIRST.org. Sources linked above.

Related: Microsoft August 2026 Patch Tuesday and CVE-2026-68820 · Metabase zero-day unauthenticated SQL injection to admin

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.