Active exploitation of SharePoint RCE vulnerability CVE-2026-50522 enables persistent access
Threat actors are actively exploiting CVE-2026-50522, a critical remote code execution vulnerability in Microsoft SharePoint, to extract machine keys and maintain persistence. Security researchers warn that patching alone is insufficient if the server was compromised prior to the update, as attackers may have already established backdoors. This marks the third SharePoint vulnerability exploited in July 2026, highlighting a significant escalation in targeting of the platform.
Score Breakdown
Part of 2 situations
Multiple Critical Vulnerabilities Actively Exploited Across Enterprise Software
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.