news.mlab.sh
Back to the feed
vulnerability

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

High
Summary

A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited in the wild, allowing attackers to execute arbitrary code on SharePoint servers. Threat actors are specifically targeting SharePoint machine keys to maintain long-term access, highlighting the need for immediate patching and credential rotation beyond simply applying Microsoft’s Patch Tuesday updates.

A critical remote code execution vulnerability, CVE-2026-50522, is currently being exploited by threat actors. This vulnerability stems from deserialization of untrusted data and allows an authenticated Site Owner to inject and execute code remotely on a SharePoint Server. Threat intelligence firm Defused initially detected exploitation attempts targeting this zero-day vulnerability on July 17th, later confirming it was CVE-2026-50522 on July 20th. Security firm WatchTowr subsequently confirmed active exploitation shortly after a Proof of Concept (PoC) exploit was released. Attackers are leveraging this vulnerability to steal SharePoint machine keys, providing them with persistent access to systems. Microsoft has not yet updated its advisory to reflect the in-the-wild exploitation, a common practice for the company following attack detection. Several other SharePoint vulnerabilities – CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659 – have also been exploited in recent weeks. The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about attacks targeting SharePoint instances, and their Known Exploited Vulnerabilities (KEV) catalog currently lists 13 SharePoint flaws, including five added this year. This situation is compounded by the exploitation of vulnerabilities in related products, such as ServiceNow and SonicWall, which have been used to deliver custom malware.

Read the full article at SecurityWeek