A critical Microsoft SharePoint remote code execution flaw, CVE-2026-50522 (CVSS 9.8), is being actively exploited against on-premises deployments after Microsoft released fixes for affected versions of SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Subscription Edition. The vulnerability stems from unsafe deserialization of untrusted data and can be triggered through unauthenticated requests, making internet-facing SharePoint farms particularly exposed. Researchers reported likely real-world exploitation against honeypots, and public proof-of-concept code is now available.
Reporting indicates attackers have targeted on-prem SharePoint instances and, in some cases, stolen machine keys to help preserve long-term access. The flaw was originally demonstrated during Pwn2Own Berlin, where exploit code was shown and shared with Microsoft before the vendor issued patches. Organizations running exposed SharePoint servers have been urged to apply the fixed versions immediately and, if patching cannot be completed at once, restrict external access and review logs for suspicious requests to SharePoint sign-in pages.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Public exploit code for CVE-2026-50522 became available, increasing the risk to internet-facing SharePoint servers. Reports said the circulating proof of concept raised urgency for organizations to deploy Microsoft's patch quickly.
Researchers reported likely active exploitation of the SharePoint flaw against on-premises deployments and honeypots using unauthenticated requests. watchTowr said attackers were stealing machine keys to maintain long-term access.
During Pwn2Own Berlin in May, researchers demonstrated a working exploit for CVE-2026-50522 and provided the details to Microsoft. The flaw affects on-premises Microsoft SharePoint Server deployments and enables remote code execution via unsafe deserialization.
Microsoft released a patch for CVE-2026-50522 on 2026-07-14. The fix applies to affected on-premises SharePoint versions including Enterprise Server 2016, Server 2019, and Subscription Edition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcevulert.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcedarkwebinformer.com
Open sourcebleepingcomputer.com
Open sourcedecipher.sc
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.