Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Summary
Microsoft SharePoint Server is experiencing active exploitation of a critical deserialization vulnerability, CVE-2026-50522. This flaw, which has a CVSS score of 9.8, allows an unauthenticated attacker to execute code remotely.
IFF Assessment
FOE
This vulnerability allows an attacker to remotely execute code, posing a significant threat to organizations using Microsoft SharePoint.
Severity
9.8
Critical
Defender Context
Organizations using Microsoft SharePoint should prioritize patching CVE-2026-50522 immediately, as it is under active exploitation. Defenders should monitor their networks for any signs of compromise related to this vulnerability and ensure robust security measures are in place.