Critical SharePoint Bug Under Attack
The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14.

The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14.
July 21, 2026 | 1 min read

Researchers are warning that threat actors are actively exploiting a recent SharePoint critical vulnerability that Microsoft patched last week in its July Patch Tuesday release.
The flaw (CVE-2026-50522) affects SharePoint Enterprise Server 2016 and 2019 as well as SharePoint Subscription service. Microsoft released the fix for this vulnerability on July 14 and at the time it was not being exploited in the wild. That changed in the last couple of days.
“watchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” researchers at watchTowr said Tuesday.
The vulnerability can lead to remote code execution and Microsoft has listed it as critical.
“Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network,” the Microsoft advisory says.
This bug was disclosed as part of the Pwn2Own Berlin contest in May, which means there was working exploit code then and it was given to Microsoft as part of the disclosure process.
“CVE-2026-50522 was demonstrated during Pwn2Own Berlin, so it’s odd to see Microsoft list it as “Exploit Maturity Unknown” since we literally handed them a working exploit. Just another reason to do your own risk assessment and not rely 100% on the vendor. If you have any Internet accessible SharePoint servers, test and deploy this patch quickly,” Dustin Childs of the Zero Day Initiative said.
Now that exploit code is circulating, it’s imperative for organizations with vulnerable SharePoint instances to update as soon as possible.
July 21, 2026 | 1 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.