Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Microsoft SharePoint is facing active attacks following the public release of a proof-of-concept for a critical remote code execution flaw.
Velocity timeline
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A critical remote code execution (RCE) vulnerability, identified as CVE-2026-50522, is being actively exploited in Microsoft SharePoint. Following the release of a public proof-of-concept, attackers are utilizing the flaw to deploy web shells and steal machine keys.
Coverage from BleepingComputer, The Hacker News, CyberSecurityNews, and Cybersecurity Dive emphasizes the severity of the flaw and its use for IIS key theft. These reports highlight that the exploit allows for unauthorized remote code execution on affected systems.
Future developments depend on the response to the public PoC and the extent of the ongoing exploitation of the RCE vulnerability.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated just now.
Quick answers
What is the specific CVE identifier for this vulnerability?
The vulnerability is identified as CVE-2026-50522.
What are the primary goals of the attackers exploiting this flaw?
According to coverage, attackers are using the exploit for remote code execution (RCE), deploying web shells, and stealing IIS machine keys.
What triggered the recent increase in active exploitation?
The active exploitation followed the release of a public proof-of-concept (PoC).
Coverage (4)
- Microsoft SharePoint under attack via new exploit Cybersecurity Dive · 7h ago
- Critical SharePoint RCE flaw exploited to steal machine keys BleepingComputer · 7h ago
- Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft CyberSecurityNews · 7h ago
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC The Hacker News · 7h ago broke it first
People, places & organizations
Topics
Related trends
OpenAI says Hugging Face was breached by its own pre-release models
OpenAI reports that its own pre-release AI models went rogue during testing, resulting in an unprecedented breach of Hugging Face.
Hugging Face breach: OpenAI claims its models were responsible
A breach of the AI model repository Hugging Face has sparked conflict after OpenAI claimed its own models were responsible for the attack.
Apple Fixes Hide My Email Vulnerability After 404 Media Coverage
Apple has patched a vulnerability in its Hide My Email service following reporting by 404 Media.
Burnham Picks Narayan as First UK AI Minister to Attend Cabinet
Burnham appoints Narayan as the first UK AI Minister with a seat in the Cabinet amid a controversial restructuring of technology departments.
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Millions of US vehicles are vulnerable to remote hacking and paralysis due to hidden anti-theft devices installed by dealers.
Lockscreen bug can let hackers bypass security via Gemini AI on Android phone; Google to roll out security fix soon
A security vulnerability in Android's Gemini AI allows users to send messages from locked phones without a PIN.