Microsoft
CVE-2026-50522 went from patch to known exploitation with long-term consequences in days, as patch volumes continue to swell.
CISA on Tuesday formally confirmed active exploitation of CVE-2026-50522, an unauthenticated flaw that lets attackers force SharePoint to process maliciously crafted data and execute code remotely.
Microsoft released patches for the affected versions of SharePoint on July 14. But within days it became a matter of incident response, with the need to rotate keys and hunt for payloads that may have been left behind, rather than just patching. By July 20th, security group watchTowr said, it was seeing exploit attempts on its honeypots.
Based on what it observed, attackers were "pulling SharePoint machine keys via a single request," watchTowr said.
Join peers managing over $100 billion in annual IT spend and subscribe to unlock full access to The Stack’s analysis and events.
Already a member? Sign in