another SharePoint RCE is being exploited right now — CVE-2026-50522 is a 9.8 and the exploit is public

An unauthenticated attacker can run code on your SharePoint server with a single crafted request. There's a public PoC, it's under active…

Aliteq
Priya Nair · Software & Systems Editor

What you need to know

CVE-2026-50522 · CVSS 9.8 (Critical) — unauthenticated remote code execution in SharePoint Server.

What you need to know

Under active exploitation after a public PoC was released — this is not theoretical.

What you need to know

No auth, no user interaction — one crafted HTTP request runs code as the SharePoint service account.

What you need to know

Affected: SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016.

What you need to know

Fix exists: Microsoft's July 14, 2026 update. Apply it immediately, then hunt for compromise.

What you need to know

It's part of a wave of SharePoint attacks — the fourth SharePoint bug exploited in a month.

Aliteq

Read the full story

another SharePoint RCE is being exploited right now — CVE-2026-50522 is a 9.8 and the exploit is public

Read the full story on Aliteq