Government cyber authorities in Colombia and Panama warned about a critical Microsoft SharePoint Server vulnerability affecting on-premises deployments, with Panama identifying the flaw as CVE-2026-50522. The bug is an unauthenticated remote code execution issue tied to CWE-502 insecure deserialization in SharePoint Server 2016, 2019, and Subscription Edition, reportedly reachable through the /_trust/default.aspx WS-Federation endpoint using crafted tokens. The alerts emphasize that SharePoint Online is not affected, while Internet-exposed on-premises servers face the highest risk.
Microsoft released patches, but public reporting cited subsequent proof-of-concept activity followed by broad exploitation of exposed servers, prompting CISA to add CVE-2026-50522 to its Known Exploited Vulnerabilities catalog. CSIRT Panamá warned that attackers could steal IIS machine keys, forge authentication tokens, and maintain access even after patching unless affected organizations also rotate keys and restart IIS or SharePoint services. Defenders were urged to patch immediately, assume exposed servers may already be compromised, reduce Internet exposure, and review logs and webshell indicators for signs of intrusion.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
COLCERT issued security alert AL-20260804-108 identifying a critical vulnerability in Microsoft SharePoint Server. The supplied content does not include a CVE, affected versions, exploitation status, or remediation details.
CSIRT Panamá published an advisory warning that CVE-2026-50522 is being actively exploited against on-premises Microsoft SharePoint servers. The notice described the reported abuse of the /_trust/default.aspx WS-Federation endpoint and recommended patching, key rotation, service restarts, and reducing Internet exposure.
CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog, reflecting active exploitation of the SharePoint flaw. The vulnerability can enable remote code execution and subsequent persistence if IIS machine keys are stolen and not rotated.
Microsoft published the official fix for CVE-2026-50522, a critical unauthenticated remote code execution flaw in on-premises SharePoint Server 2016, 2019, and Subscription Edition. The vulnerability does not affect SharePoint Online.
COLCERT published follow-up advisory AL-20250728-069 بشأن a critical Microsoft SharePoint vulnerability. The visible excerpt only confirms the advisory and its follow-up nature, without technical details.
COLCERT published alert AL-20250720-067 identifying a critical zero-day vulnerability affecting Microsoft SharePoint Server. The supplied content does not include a CVE, affected versions, or mitigation details.
According to public reporting cited by CSIRT Panamá, a proof of concept for CVE-2026-50522 was later published and led to mass, indiscriminate exploitation of Internet-exposed SharePoint servers. The content does not explicitly anchor the PoC publication date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
colcert.gov.co
Open sourcecert.pa
Open sourcecolcert.gov.co
Open sourcecolcert.gov.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.