INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Public Exploitation of SharePoint RCE Vulnerability CVE-2026-50522

| 2026-07-21 14:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The critical Microsoft SharePoint vulnerability, CVE-2026-50522, is being actively exploited following the release of a public proof-of-concept (PoC) code. This deserialization-based remote code execution bug can be triggered without authentication or user interaction and stems from the deserialization of untrusted data. The vulnerability has been demonstrated live at Pwn2Own Berlin, with working exploits handed to Microsoft. Active exploitation is also observed on-premises by cybersecurity firms Defused Cyber and watchTowr, targeting a .NET deserialization payload through a SharePoint sign-in endpoint. This critical vulnerability requires no authentication, consistent with its unauthenticated remote code execution profile, making it a high-severity threat.
Technical Mitigations AI-generated
* Apply Microsoft's July 2026 Patch Tuesday updates immediately: Organizations should apply the available security updates to patch critical SharePoint RCE vulnerability CVE-2026-50522 as soon as possible. * Rotate machine keys and other potentially exposed credentials: Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise. * Use secure coding practices: Organizations should ensure that their development teams follow secure coding practices, such as validating user input and using deserialization protection mechanisms, to reduce the risk of exploitation. * Implement a web application firewall (WAF): WAFs can help block malicious traffic and prevent attacks from exploiting vulnerabilities like CVE-2026-50522. * Monitor for suspicious activity: Organizations should regularly monitor their SharePoint servers for suspicious activity, such as unauthorized access or machine key theft, to detect potential exploitation attempts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

we•••••.config
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56164CVE-2026-56164 CVE-2026-25089CVE-2026-25089 CVE-2026-39808CVE-2026-39808 CVE-2026-45659CVE-2026-45659 CVE-2026-58644CVE-2026-58644 CVE-2026-20963CVE-2026-20963 CVE-2026-32201CVE-2026-32201 CVE-2026-50522CVE-2026-50522
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎March 2026
Threat actors used a known exploited vulnerability in SharePoint to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in March 2026.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
vulnerability CVE-2026-20963
‎April 2026
Threat actors used a previously disclosed vulnerability in Microsoft SharePoint Server to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
tactic T1584.004 - Server
vulnerability CVE-2026-32201
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎July 14, 2026
Threat actors used a remote exploit to target Microsoft SharePoint Server Subscription Edition and Microsoft SharePoint Enterprise Server 2016 versions.
tactic T1584.004 - Server
organisation Microsoft SharePoint
general_metric 2016 Patches
‎2026/07/14
Threat actors used T1584.004 - Server to target a SharePoint server via critical Remote Code Execution (RCE) vulnerability CVE-2026-50522 under active exploitation after public proof of concept.
tactic T1584.004 - Server
‎Jul 17, 2026
Threat actors exploited CVE-2026-50522 in a critical SharePoint vulnerability to gain unauthorized access.
‎July 19, 2026
Threat actors used a previously patched vulnerability (CVE-2026-50522) in Microsoft SharePoint Server to target Federal agencies.
tactic T1584.004 - Server
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
attribution Vulnerability / Enterprise Security
attribution Microsoft SharePoint
attribution Federal Civilian Executive Branch
attribution FCEB
general_metric 17  Jul
‎July 20th
WatchTowr identified proof-of-concept exploit code for CVE-2026-50522 on July 20th.
‎Jul 21, 2026
Threat actors exploited CVE-2026-50522 in a critical SharePoint vulnerability to gain unauthorized access.
‎2026/07/21
Threat actors used a public proof-of-concept (PoC) exploit code to target Microsoft SharePoint Server, exploiting the critical deserialization of untrusted data vulnerability CVE-2026-50522.
organisation SharePoint RCE
infrastructure 9.8
organisation Microsoft SharePoint
organisation PoC
organisation CVE-2026-50522
organisation CVE-2026
organisation Cybersecurity
organisation CVE-2026-32201
organisation CVSS
organisation Internet Information Services
organisation Microsoft
organisation SharePoint Central Administration
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
organisation SharePoint
organisation Attacker Eye
organisation SecurityAffairs
organisation Fortinet FortiSandbox
organisation KEV
organisation SharePoint Servers
‎July 2026
Threat actors are exploiting CVE-2026-50522 to deliver a .NET deserialization payload to a SharePoint sign-in endpoint.
vulnerability CVE-2026-50522
organisation Vulnerability / Web Security
tactic T1584.004 - Server
organisation Microsoft
general_metric 21  Jul
general_metric 9.8 score
vulnerability CVE-2026-56164
vulnerability CVE-2026-58644
infrastructure 5.3
infrastructure 9.8
organisation CVE-2026
general_metric 5.3 third vulnerability
organisation SharePoint
organisation Site Owner
infrastructure Microsoft Office
organisation Microsoft Office SharePoint
organisation Internet Information Services
organisation DEVCORE
organisation Network
organisation LinkedIn
organisation Microsoft SharePoint
organisation PoC
Tactical Metrics
Metrics
infrastructure
‎Microsoft Office
Affected Product
Metrics
infrastructure
‎5.3
Software Version
Metrics
infrastructure
‎9.8
Software Version