// Alert

Microsoft 365 threat report

Microsoft SharePoint vulnerability CVE-2026-50522 (CVSS 9.8) is under active exploitation following public proof-of-concept release. The critical deserialization flaw allows authenticated attackers to execute arbitrary code remotely and steal machine keys for persistence. watchTowr reports active exploitation against on-premises SharePoint deployments. Patching is critical, and credential rotation is advised for potentially exposed assets.

// Get alerts for Microsoft 365