// Microsoft AzureCRITICAL
CVE-2026-50522, a critical remote-code-execution vulnerability in Microsoft SharePoint Server, is under active exploitation following the release of a public proof-of-concept exploit. Attackers with Site Owner authentication can execute arbitrary code and steal machine keys for persistent access. The flaw affects all supported on-premises SharePoint versions (Subscription Edition, 2019, and 2016). CISA reports multiple SharePoint vulnerabilities being exploited in coordinated campaigns.
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation(opens in a new tab)
- Critical SharePoint RCE flaw exploited to steal machine keys(opens in a new tab)
- Another SharePoint RCE exploited: Patch, then rotate your machin(opens in a new tab)
- Critical SharePoint RCE flaw exploited to steal machine keys(opens in a new tab)
- Public PoC triggers active exploitation of critical SharePoint R(opens in a new tab)
- Fourth SharePoint Vulnerability Exploited in Past Month's Wave o(opens in a new tab)
// Get alerts for Microsoft Azure