// Alert

Microsoft Azure threat report

CVE-2026-50522, a critical remote-code-execution vulnerability in Microsoft SharePoint Server, is under active exploitation following the release of a public proof-of-concept exploit. Attackers with Site Owner authentication can execute arbitrary code and steal machine keys for persistent access. The flaw affects all supported on-premises SharePoint versions (Subscription Edition, 2019, and 2016). CISA reports multiple SharePoint vulnerabilities being exploited in coordinated campaigns.

// Get alerts for Microsoft Azure