CVE Tools
Back to feed
Exploited in the wild SharePoint Server rce Microsoft zero-day

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Microsoft has confirmed that a critical vulnerability in SharePoint Server, CVE-2026-50522, is currently being actively exploited. This flaw allows unauthenticated attackers to execute arbitrary code remotely through deserialization of untrusted data. A proof-of-concept (PoC) exploit was recently made public, enabling threat actors to extract SharePoint machine keys and maintain persistent access. The vulnerability affects all supported on-premises versions of SharePoint Server and carries a CVSS score of 9.8. Security experts warn that patching alone is insufficient—defenders should also rotate credentials for potentially compromised systems.