Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Patch Now! Hackers actively targeting Critical SharePoint RCE, researchers warn

Active exploitation of remote code execution bug CVE-2026-50522 is underway, and patching alone may not be enough to stop it.

Wed, 22 Jul 2026
Patch Now! Hackers actively targeting Critical SharePoint RCE, researchers warn

Security researchers are currently observing active, in-the-wild exploitation of a Critical remote code execution vulnerability in Microsoft’s SharePoint platform.

The vulnerability in question, CVE-2026-50522, was disclosed by Microsoft on July 15 and has a CVSS score of 9.8.

At the time, Microsoft warned that, if successfully exploited, “an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server”.

 
 

“The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.”

At the time of disclosure, Microsoft had not detected any exploitation, but it did observe that exploitation was “more likely”.

Fast forward to July 20, and it looks like Microsoft’s judgement was correct.

“watchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the cyber security firm said via post to LinkedIn.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability.

“Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.”

According to watchTowr, the attackers – who remain unknown – are pulling machine keys with a single request.

“Patching is not enough, defenders should rotate credentials on any assets that may have been exposed,” watchTowr warned.

CVE-2026-50522 is one of several SharePoint vulnerabilities currently being exploited by malicious actors, with the US Cybersecurity & Infrastructure Security Agency recently warning of three such vulnerabilities in the firing line.

“CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorised access to on-premises SharePoint Server instances,” CISA said in an advisory earlier this month.

“These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialisation techniques, to gain persistence and deploy malware.

“Organisations should monitor affected SharePoint Servers closely for any signs of exploitation or unusual activity.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.