Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
CVE-2026-50522 is a critical (CVSS 9.8) Remote Code Execution vulnerability in Microsoft SharePoint Server involving deserialization of untrusted data, currently under active exploitation. WatchTowr and Defused Cyber report that attackers are leveraging public Proof-of-Concept (PoC) exploits to steal IIS machine keys for persistent access without requiring authentication. This is the third SharePoint vulnerability patched in July 2026 to see active exploitation, following CVE-2026-56164 and CVE-
Analysis
TL;DR
- CVE-2026-50522 is a critical (CVSS 9.8) Remote Code Execution vulnerability in Microsoft SharePoint Server involving deserialization of untrusted data, currently under active exploitation.
- WatchTowr and Defused Cyber report that attackers are leveraging public Proof-of-Concept (PoC) exploits to steal IIS machine keys for persistent access without requiring authentication.
- This is the third SharePoint vulnerability patched in July 2026 to see active exploitation, following CVE-2026-56164 and CVE-2026-58644, which were previously weaponized as zero-days.
- CISA warns that these flaws affect all supported on-premises SharePoint versions (2016, 2019, Subscription Edition) and enable post-exploitation activities like malware deployment.
Why It Matters
This incident highlights the severe risk of delayed patching for high-severity vulnerabilities in widely deployed enterprise infrastructure, particularly when public PoCs are immediately available. For security practitioners, it underscores the necessity of immediate credential rotation and monitoring for anomalous deserialization traffic, as patching alone does not mitigate damage already inflicted by active attackers.
Technical Details
- Vulnerability Mechanism: CVE-2026-50522 allows remote code execution via deserialization of untrusted data, enabling unauthorized code injection by attackers with at least Site Owner privileges or potentially unauthenticated users depending on the specific attack vector observed.
- Exploit Activity: Threat actors are executing single-request attacks to extract SharePoint/IIS machine keys, facilitating session hijacking and persistent access across the network.
- Affected Scope: All supported on-premises versions of SharePoint Server, including Subscription Edition, 2019, and 2016, are vulnerable to these combined exploitation efforts.
- Related Vulnerabilities: The current exploitation campaign is part of a broader wave affecting CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, indicating a coordinated focus on SharePoint's deserialization and authentication mechanisms.
Industry Insight
- Immediate Remediation Priority: Organizations must prioritize patching SharePoint servers and rotating all associated machine keys and credentials immediately, as passive patching is insufficient once keys are stolen.
- Enhanced Monitoring: Security teams should implement strict monitoring for unusual deserialization patterns and outbound connections from SharePoint servers to detect post-exploitation activities like malware deployment.
- Zero-Day Preparedness: The rapid transition of these vulnerabilities from discovery to active exploitation suggests that defenders should assume public disclosures of critical infrastructure flaws may be accompanied by immediate, widespread attack campaigns.
Disclaimer: The above content is generated by AI and is for reference only.