// Microsoft 365CRITICAL
Microsoft SharePoint vulnerability CVE-2026-50522 (CVSS 9.8) is under active exploitation following public proof-of-concept release. The critical deserialization flaw allows authenticated attackers to execute arbitrary code remotely and steal machine keys for persistence. watchTowr reports active exploitation against on-premises SharePoint deployments. Patching is critical, and credential rotation is advised for potentially exposed assets.
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation(opens in a new tab)
- Critical SharePoint RCE flaw exploited to steal machine keys(opens in a new tab)
- Fourth SharePoint Vulnerability Exploited in Past Month's Wave o(opens in a new tab)
- Another SharePoint RCE exploited: Patch, then rotate your machin(opens in a new tab)
- Week in review: ServiceNow pre-auth RCE exploited in the wild, H(opens in a new tab)
// Get alerts for Microsoft 365