CRITICAL
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A third SharePoint Server flaw patched by Microsoft in its July 2026 Patch Tuesday update, CVE-2026-50522 (CVSS 9.8), has come under active exploitation following publication of a proof-of-concept, according to watchTowr. The bug is a deserialization of untrusted data in Microsoft Office SharePoint that lets an unauthorized attacker execute code over the network. Microsoft credited DEVCORE for the original discovery. Organizations should confirm they’ve applied the July patch.