Visualização de leitura

Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code.

A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.

Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.

CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data. CVE-2026-50522 was demonstrated live at Pwn2Own Berlin, meaning a working exploit was handed to Microsoft. Despite that, the advisory lists exploit maturity as unknown.

Organizations should apply the available security updates immediately.

watchTowr observed active exploitation of CVE-2026-50522 targeting on-premises Microsoft SharePoint servers shortly after public exploit code was released. Attackers are using the flaw to steal SharePoint machine keys in a single request, enabling persistent access even after patching. Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.

“On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability. Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.” watchTowr wrote on LinkedIn. “Attackers are pulling SharePoint machine keys via a single request. Patching is not enough, defenders should rotate credentials on any assets that may have been exposed.”

Cybersecurity firm Defused Cyber also spotted threat actors exploiting CVE-2026-50522 to deliver a .NET deserialization payload through a SharePoint sign-in endpoint. The observed attacks require no authentication, consistent with the vulnerability’s unauthenticated remote code execution profile.

🚨 Update to our Jul 17 SharePoint report: we now assess the undocumented deserialization vector on our honeypots as likely CVE-2026-50522.

The captured requests carry no authentication material, matching 50522's unauthenticated profile. Microsoft describes the paired… https://t.co/t2EXqemSPr

— Defused (@DefusedCyber) July 20, 2026

In early July, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft SharePoint Server flaw, tracked as CVE-2026-45659 (CVSS score v3.1 of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.

At the end of May, Microsoft released security updates to patch the high-severity SharePoint vulnerability CVE-2026-45659 that could allow remote code execution. The flaw does not require complex conditions for exploitation, making it a serious risk for unpatched systems. Organizations using Microsoft SharePoint should apply the updates as soon as possible.

The root cause is deserialization of untrusted data.

In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Microsoft SharePoint Server flaw, tracked as CVE-2026-32201, to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-32201 (CVSS score of 6.5) is a spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS). While details are limited, it could allow attackers to view or modify exposed information. Microsoft has not disclosed how widespread exploitation is, but given the potential impact, organizations, especially those with internet-facing SharePoint servers—should prioritize testing and applying the patch quickly.

In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another SharePoint issue, tracked as CVE-2026-20963, its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft)

U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities (KEV) catalog.

  • CVE-2026-25089 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability  
  • CVE-2026-39808 (CVSS score of 9.8) Fortinet FortiSandbox OS Command Injection Vulnerability  
  • CVE-2026-58644 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

This week, Microsoft’s July 2026 Patch Tuesday addressed the SharePoint remote code execution bug CVE-2026-58644, which can be triggered without authentication or user interaction. The flaw stems from the deserialization of untrusted data.

“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.” reads the advisory. “In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server.”

Microsoft confirmed it is aware of active exploitation of this vulnerability.

The second issue added to the KeV catalog is an OS command injection flaw, tracked as CVE-2026-25089, in FortiSandbox products. The vulnerability could allow remote, unauthenticated attackers to send specially crafted HTTP requests and execute arbitrary commands on affected devices. Adham El Karn of Fortinet Product Security team discovered the vulnerability.

The last issue added to the catalog, tracked as CVE-2026-39808, is an OS command injection flaw.

“An Improper Neutralization of Special Elements used in an OS Command (‘OS command injection’) vulnerability [CWE-78] in FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.” reads the advisory.

Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of this vulnerability within a 24-hour window.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to urgently fix these flaws by July 19, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

❌