CVE Tools
Back to feed
Exploited in the wild SharePoint Server network-edge Microsoft rce

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

A new SharePoint vulnerability, CVE-2026-50522, is being actively exploited in real-world attacks—marking the fourth such flaw found under attack in just one month. Microsoft addressed the issue on July 14 as part of its monthly security updates, labeling it a critical remote code execution flaw due to improper handling of untrusted data. Attackers can exploit this flaw by authenticating as a Site Owner and injecting malicious code onto the server. Threat intelligence firm Defused first reported signs of exploitation, followed by confirmation from WatchTowr that attackers are stealing machine keys for persistent access. While Microsoft has not yet updated its advisory to reflect active exploitation, CISA has urged immediate patching of similar SharePoint vulnerabilities.