A fourth SharePoint vulnerability has been exploited in a wave of attacks that have shaken organizations worldwide. The flaw, tracked as CVE-2026-50522, was patched by Microsoft on July 14 with its latest Patch Tuesday updates, but threat actors were quick to capitalize on it.
Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming from the deserialization of untrusted data. In essence, this means that an attacker can exploit the flaw to inject and execute arbitrary code remotely on a SharePoint Server, even if they are only authenticated as a Site Owner. This type of attack is particularly concerning because it allows threat actors to gain long-term access to sensitive data.
Threat intelligence firm Defused was the first to observe exploitation attempts targeting what appeared to be a zero-day SharePoint vulnerability. Initially, the company reported that its honeypots had seen exploitation attempts against an unpatched vulnerability, but later updated their findings to indicate that the targeted flaw was likely CVE-2026-50522.
On July 20, security firm WatchTowr confirmed active exploitation of the vulnerability, noting that attackers are using it to steal machine keys and retain long-term access. The company emphasized that patching alone is not enough, and that defenders should rotate credentials on any assets that may have been exposed. This warning echoes recent guidance from CISA, which warned organizations about attacks targeting SharePoint instances.
The exploitation of CVE-2026-50522 marks the fourth SharePoint vulnerability to be exploited in the past month, following CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659. These vulnerabilities are particularly concerning because they highlight the ease with which attackers can exploit common web applications like SharePoint.
Microsoft has yet to update its advisory for CVE-2026-50522 to confirm in-the-wild exploitation, but it’s not uncommon for the tech giant to delay updating its advisories after attacks are detected. The company’s patching efforts do provide a critical layer of protection against these types of attacks, however.
The recent wave of SharePoint vulnerabilities exploited by threat actors serves as a stark reminder that even seemingly robust systems can be vulnerable to attack. As we’ve seen with other web applications like ServiceNow and WordPress, it’s clear that attackers are actively seeking out and exploiting unpatched vulnerabilities.
In the face of these threats, organizations should take proactive steps to protect their SharePoint instances. This includes ensuring that all patches are up-to-date, rotating credentials on sensitive assets, and implementing robust security measures to prevent unauthorized access. By taking these precautions, organizations can reduce their risk exposure and minimize the potential for damage in the event of an attack.
Source: SecurityWeek — 2026-07-22