Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
A critical remote code execution vulnerability in Microsoft SharePoint (CVE-2026-50522) is being actively exploited following the release of a public PoC.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Microsoft SharePoint is currently under attack via a critical remote code execution (RCE) flaw identified as CVE-2026-50522. The vulnerability is being actively exploited in the wild following the availability of a public proof-of-concept.
Coverage from BleepingComputer, The Hacker News, CyberSecurityNews, and Cybersecurity Dive emphasizes that attackers are using the flaw to deploy web shells and steal machine keys, specifically IIS keys. Further developments depend on the active exploitation of the CVE-2026-50522 vulnerability and the continued use of the public PoC to target SharePoint installations.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated just now.
Quick answers
What is the specific vulnerability affecting SharePoint?
The vulnerability is identified as CVE-2026-50522, a critical remote code execution (RCE) flaw.
What are attackers achieving through this exploit?
Attackers are using the exploit for remote code execution, the installation of web shells, and the theft of IIS machine keys.
Why has the exploitation of this flaw increased?
According to coverage from The Hacker News, the flaw is under active exploitation following the release of a public proof-of-concept (PoC).
Coverage (4)
- Microsoft SharePoint under attack via new exploit Cybersecurity Dive · 8h ago
- Critical SharePoint RCE flaw exploited to steal machine keys BleepingComputer · 8h ago
- Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft CyberSecurityNews · 8h ago
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC The Hacker News · 8h ago
Topics
Related trends
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers are exploiting recently patched WordPress vulnerabilities via 'WP2Shell,' leaving millions of websites open to remote takeover.
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical pre-authentication remote code execution vulnerability known as 'wp2shell' is impacting WordPress Core.
CISA Urges SharePoint Hardening After New Exploitations
9 news sources are covering this Technology story right now — Archynetys is tracking how fast it spreads.