Cybersecurity & Data Protection · Industry Watch

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

thehackernews.com · 21 July 2026, 20:27 IST

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE

This headline and summary belong to the original publisher and are shown here with attribution for our readers; the complete article is available only at the source linked above. Curation and any commentary are by Addroit Nexus and do not imply endorsement by the publisher. Spotted an error or want a story removed? Tell us and we act quickly.

Get Started

Let's build something that lasts.

From a single landing page to a rack in our Lucknow edge data center — talk to a real engineer today and get a straight answer.