Security · 5h ago
Critical SharePoint RCE Flaw Under Active Attack After PoC Release
Microsoft's July 2026 Patch Tuesday addressed CVE-2026-50522, a critical deserialization vulnerability in SharePoint Server with a CVSS score of 9.8. Security firm watchTowr reports active exploitation following the public release of a proof-of-concept exploit. The flaw allows unauthenticated remote code execution over a network.
Meridian48 take
The rapid exploitation after PoC publication underscores the risk of delayed patching for critical SharePoint vulnerabilities, especially given the platform's widespread enterprise use.
Read the full reporting
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC →
The Hacker News
sharepointrce