🔴 Critical  |  Source: The Hacker News


A critical remote code execution vulnerability in Microsoft SharePoint Server (CVE-2026-50522, CVSS 9.8) is now being actively exploited following the release of a public proof-of-concept. The flaw stems from insecure deserialisation of untrusted data, allowing an unauthenticated attacker to execute arbitrary code over the network. This follows Microsoft’s July 2026 Patch Tuesday fix, meaning organisations that have not yet patched are at significant risk.

Security Architect’s Take: Prioritise emergency patching of all on-premises SharePoint Server instances immediately, and verify patch application via your vulnerability management tooling. If patching cannot be completed within hours, consider isolating SharePoint from public internet exposure and enabling WAF rules targeting deserialisation attack patterns as a temporary control.

Original advisory: Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC