discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A critical SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in M…

By Ravie Lakshmanan·Jul 21·thehackernews.com·3 min read

Intelligence analysis by Llama

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Image: thehackernews.com

Microsoft has patched a critical SharePoint Server flaw as part of its Patch Tuesday update for July 2026, but the vulnerability has already come under active exploitation. WatchTowr has detected exploitation of the flaw against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit.

Why it matters

The exploitation of this vulnerability highlights the importance of patching and rotating credentials on affected assets to prevent persistent access.

Imagine you have a super powerful computer that can do anything you want, but someone else can also control it remotely. That's what's happening with the SharePoint Server flaw. Attackers can steal machine keys to maintain persistent access, and Microsoft has patched the issue, but it's already being exploited.

Analysis

A Third SharePoint Server Flaw in July 2026 Patch Tuesday Update

Microsoft has patched a third SharePoint Server flaw as part of its Patch Tuesday update for July 2026. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.

Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw. "In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server," Redmond said in an advisory released last week.

The tech giant also tagged CVE-2026-50522 with an exploitability assessment of "Exploitation More Likely." In a post shared on LinkedIn, watchTowr said it has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit, allowing attackers to steal machine keys to maintain persistent access.

"Attackers are pulling SharePoint machine keys via a single request," the security vendor said. "Patching is not enough; defenders should rotate credentials on any assets that may have been exposed."

Defused Cyber has also disclosed that threat actors are likely exploiting CVE-2026-50522 to deliver a .NET deserialization payload to a SharePoint sign-in endpoint. "The captured requests carry no authentication material, matching 50522's unauthenticated profile," it said.

CVE-2026-50522 is the third vulnerability in SharePoint Server after CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644 (CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has since warned that threat actors are exploiting multiple SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, to gain unauthorized access to on-premises instances.

"These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware," the agency said.

Key points

  • Microsoft has patched a critical SharePoint Server flaw as part of its Patch Tuesday update for July 2026.
  • The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint.
  • WatchTowr has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit.
  • Defused Cyber has also disclosed that threat actors are likely exploiting CVE-2026-50522 to deliver a .NET deserialization payload to a SharePoint sign-in endpoint.
The Upside

Microsoft has patched the vulnerability, and watchTowr has detected active exploitation efforts. This highlights the importance of patching and rotating credentials on affected assets to prevent persistent access.

The Downside

The exploitation of this vulnerability highlights the risks of not patching and rotating credentials on affected assets, which can lead to persistent access and further attacks.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-agentsbankingbusinesscodingcryptoeconomyeditorialenergyethicsfinance

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Jul 21, 2026

Source

thehackernews.com

Share

Topics

ai-agentsbankingbusinesscodingcryptoeconomyeditorialenergyethicsfinance

Related

More from this desk

Jul 21·thehackernews.com

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.

Jul 21·bleepingcomputer.com

Closing the Identity Gaps in Critical Infrastructure Security

The Colonial Pipeline ransomware attack in 2021 highlighted the vulnerability of critical infrastructure to cyber threats. Five years later, the lessons learned from this attack are more relevant than ever, as state-backed actors seek to disrupt critical infrastructure ne…

Jul 21·thehackernews.com

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Researchers demonstrated that open-source Android AI agents can be exploited to run code on host PCs by drawing invisible screen text and using it to slip instructions to the AI agent. This vulnerability affects five open-source mobile agent frameworks: AppAgent, AppAgent…

Jul 21·thehackernews.com

N-day is Becoming N-Hour. Patching Faster Won't Save You.

The traditional playbook for patching security vulnerabilities is no longer effective due to the rapid advancement of AI-powered exploit tools. Researchers have found that they can now turn a patch into a working exploit in under an hour, making it difficult for defenders…