Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-50522 +1 in the same advisory: …58644 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server CVE-2026-50522 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthenticated attacker to send maliciously crafted serialized data over the network and execute code on the server, reflected in its 9.8 critical CVSS score with no privileges or user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, giving attackers a foothold for follow-on actions such as data theft, lateral movement, or ransomware. Any organization running on-premises SharePoint Server is in scope, particularly deployments reachable from untrusted networks; the required action notes stakeholders must evaluate each asset's internet exposure under CISA BOD 26-04. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22 and security news headlines describe it as a critical RCE exploited in the wild, with some reports referencing exploitation after a public proof-of-concept release and an authentication bypass. The structured record lists no public PoC as confirmed, but an EPSS of 84.6% (100th percentile) underscores a very high near-term exploitation likelihood. Do: Apply Microsoft's security updates for SharePoint Server immediately per the vendor advisory, as required under CISA's KEV listing and BOD 26-04, and prioritize any SharePoint deployments that are internet-facing (federal/critical-infrastructure operators must follow BOD 26-04 timelines or discontinue unmitigated use). Until patched, restrict public access to SharePoint endpoints (VPN, firewall rules, or reverse proxy) and review IIS/application logs and running processes for signs of unauthenticated deserialization abuse. Because some reports reference an authentication bypass being chained, also verify authentication paths and monitor for follow-on attacker activity after patching. | 9.8 | 85% | KEV |
| massorder of 100,000+ on-prem SharePoint Server deployments worldwide, with tens of thousands plausibly internet-exposed | |
| CVE-2026-56164 | Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk. Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high. | 9.8 | 27% | KEV |
| masspotentially millions of users and well over 100,000 exposed installations worldwide |
Full article440 words · extracted from helpnetsecurity.com · click to collapse
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys.
“WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday.
WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and less than a week after Microsoft confirmed that CVE-2026-56164 (an privilege elevation flaw) and CVE-2026-58644 (a RCE vulnerability) are being actively exploited by attackers.
On July 17, threat intelligence firm Defused also spotted what they now believe to be CVE-2026-50522 exploitation attempts.
“The captured requests carry no authentication material, matching 50522’s unauthenticated profile. Microsoft describes the paired CVE-2026-58644 as requiring Site Owner auth, which does not fit unauthenticated traffic,” they commented on Monday.
If they are right, it means that exploitation of CVE-2026-50522 started before the PoC exploit was released, but after Microsoft pushed out fixes for both flaws – earlier this month for CVE-2026-50522 and in June 2026 for CVE-2026-58644.
Patching alone won’t lock attackers out
Attackers are continuously trying to breach SharePoint servers, as they are usually reachable from the internet, hold valuable organizational data, and are integrated with other internal systems.
Internet intelligence company Censys recently mapped internet-facing SharePoint servers and says almost all of them are SharePoint Online, which are hosted, operated and patched by Microsoft.
“Counting hosts rather than web properties, about 1,500 run the self-managed, on-premises editions, predominantly SharePoint 2019 with smaller fractions identifying as 2016 and Subscription Edition,” they noted, and said that most of these are in the US.
How many of these have received the latest security updates is impossible to tell, Censys added, because “the SharePoint response header (…) limits how precisely patch status can be assessed.”
The US Cybersecurity and Infrastructure Security Agency issued a warning last week about a slew of SharePoint vulnerabilities targeted by attackers and urged organizations running self-managed server instances to:
- Implement security updates quickly
- Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application (and monitor for detections)
- Implement a number of hardening measures
- Hunt for and remediate any intrusion artifacts before rotating IIS machine keys
Organizations that haven’t yet implemented the SharePoint updates released on July 14 should not skip that last step.
“Patching is not enough, defenders should rotate credentials on any assets that may have been exposed,” watchTowr advised.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/