Skip to main content
CyberConfirmedHighDevelopingFeatured
7.7

Active exploitation of SharePoint RCE vulnerability CVE-2026-50522 enables persistent access

Threat actors are actively exploiting CVE-2026-50522, a critical remote code execution vulnerability in Microsoft SharePoint, to extract machine keys and maintain persistence. Security researchers warn that patching alone is insufficient if the server was compromised prior to the update, as attackers may have already established backdoors. This marks the third SharePoint vulnerability exploited in July 2026, highlighting a significant escalation in targeting of the platform.

The Hacker Newsabout 7 hours agoUSCredibility 54%View source

Score Breakdown

Mosaic Score7.7
Confidence0.9
Significance0.8
Source credibility0.5
Source

Part of 2 situations

Related signals

8 found