Skip to content

You had six days to patch the latest SharePoint flaw before attackers moved in

CVE-2026-50522 went from patch to known exploitation with long-term consequences in days, as patch volumes continue to swell. 

You had six days to patch the latest SharePoint flaw before attackers moved in
Photo by Towfiqu barbhuiya / Unsplash

CISA on Tuesday formally confirmed active exploitation of CVE-2026-50522, an unauthenticated flaw that lets attackers force SharePoint to process maliciously crafted data and execute code remotely.

Microsoft released patches for the affected versions of SharePoint on July 14. But within days it became a matter of incident response, with the need to rotate keys and hunt for payloads that may have been left behind, rather than just patching. By July 20th, security group watchTowr said, it was seeing exploit attempts on its honeypots. 

Based on what it observed, attackers were "pulling SharePoint machine keys via a single request," watchTowr said.

This content is for members only

Subscribe
Add The Stack on Google