// Microsoft 365CRITICAL
Microsoft disclosed CVE-2026-50522, a critical remote code execution vulnerability in Microsoft SharePoint Server affecting all on-premises versions. The flaw enables arbitrary code execution via deserialization of untrusted data and is actively exploited by state-sponsored APT groups (Linen Typhoon, Violet Typhoon) and ransomware operators (Warlock, LockBit). Attackers deploy webshells, steal credentials, and establish persistent access; public exploit code is available and campaigns have targeted hundreds of organizations globally including US federal agencies.
// Get alerts for Microsoft 365