Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A critical remote code execution flaw in Microsoft SharePoint, CVE-2026-50522, is being actively exploited following the release of a public PoC.
🌍 Cross-language spread
PULSE detected this story across 2 language editions of the world's news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Microsoft SharePoint is currently facing an active security crisis centered on a critical remote code execution vulnerability identified as CVE-2026-50522. According to reports from The Hacker News and CyberSecurityNews, this flaw is being exploited in the wild following the release of a public proof-of-concept. The technical nature of the attack allows for a single malicious web request to transform an exposed SharePoint server into a persistent backdoor. This capability enables attackers to move from an initial web request to a full domain compromise, as detailed in analysis provided by Resecurity. The vulnerability is facilitating the deployment of web shells and the theft of critical machine keys. Multiple industry outlets are tracking the escalation of these attacks.
BleepingComputer and SC Media emphasize that the exploit is specifically being used to steal machine keys, noting that this represents the fourth recent exploit of its kind. CyberSecurityNews further highlights the multifaceted nature of the threat, which includes remote code execution and the installation of web shells. Coverage from The National CIO Review links these SharePoint vulnerabilities with Windmill vulnerabilities, suggesting that both are fueling a fresh wave of enterprise-level attacks. Other regional and specialized reports, including those from Kaseya, have listed these events within their weekly breach news summaries for the period of July 15, 2026. Understanding the context of this trend requires noting the speed at which the public proof-of-concept transitioned into active exploitation. The vulnerability is categorized as critical because it grants attackers high-level access to servers via basic web requests.
As gbhackers.com points out, the ability to establish a persistent backdoor means that once a server is breached, the attackers can maintain access even after some initial remediation efforts. The focus on IIS key theft suggests that attackers are targeting the underlying infrastructure of the server to deepen their penetration into the corporate network, moving beyond the application layer to the domain level. Looking ahead, the primary focus for enterprise security teams is the mitigation of CVE-2026-50522 to prevent further domain compromises. Organizations are monitoring for signs of web shells and the unauthorized extraction of machine keys, as these are the primary indicators of a successful breach. Because the vulnerability is being actively exploited in the wild, the priority remains identifying exposed SharePoint servers that may have already been targeted by the malicious web requests described in the coverage. Future reports will likely track whether the exploitation of this flaw continues to rise in tandem with the Windmill vulnerabilities mentioned by The National CIO Review.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 51d ago.
Quick answers
What is the CVE identifier for the SharePoint vulnerability?
The vulnerability is identified as CVE-2026-50522.
What can attackers achieve using this exploit?
Attackers can achieve remote code execution, install web shells, steal machine keys, and potentially move from a web request to a full domain compromise.
How is the vulnerability being triggered?
According to coverage, a single malicious web request can be used to turn an exposed SharePoint server into a persistent backdoor.
Coverage (11)
- Windmill and SharePoint Vulnerabilities Fuel Fresh Enterprise Attacks The National CIO Review · 56d ago
- SharePoint vulnerability steals machine keys; fourth recent exploit SC Media · 56d ago
- Die Woche in den Nachrichten zu Datenschutzverletzungen Kaseya · 56d ago
- Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild CyberSecurityNews · 56d ago
- From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks Resecurity · 56d ago
- The Week in Breach News: July 15, 2026 Kaseya · 56d ago
- One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor gbhackers.com · 56d ago
- Critical SharePoint RCE flaw exploited to steal machine keys BleepingComputer · 56d ago
- Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft CyberSecurityNews · 56d ago
- Microsoft SharePoint under attack via new exploit Cybersecurity Dive · 56d ago
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC The Hacker News · 56d ago
Topics
Related trends
ClickFix attacks are tricking Mac and Windows users into hacking themselves
ClickFix attacks trick Mac and Windows users into compromising their own systems via hijacked accounts and ads.
Cybersecurity stocks get a jolt on gloomy AI warnings from CEOs of Anthropic and OpenAI
1 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
Revolut confirms customer data breach through fake government requests
7 news sources are covering this Business story right now — PULSE is tracking how fast it spreads.
AI stocks get drilled because of Anthropic CEO Dario Amodei's 3,800 word warning
AI stocks plunge globally as prominent chief executives issue prominent new warnings regarding development risks.
Has Your Accent Just Become a Security Vulnerability?
Scammers are utilizing artificial intelligence to clone human voices, raising urgent security concerns across multiple reports.
GTA 6 Developer Is Fighting Drones And Hackers To Keep The Game’s Secrets Safe
1 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.