Microsoft SharePoint Vulnerability CVE-2026-50522 Under Active Attack
A critical vulnerability in Microsoft SharePoint has been discovered and is being actively exploited by sophisticated threat actors. The vulnerability, identified as CVE-2026-50522, enables remote code execution via deserialization of untrusted data and affects all supported on-premises versions of Microsoft SharePoint Server.
Attackers are leveraging this flaw to gain unauthorized access, steal sensitive credentials, deploy webshells, and establish persistent footholds within enterprise environments. The exploitation is low in complexity and can be automated, making it a significant concern for organizations that have not applied the latest security patches.
Recent campaigns exploiting CVE-2026-50522 have been attributed to a mix of state-linked and criminal actors, including Chinese APT groups such as Linen Typhoon and Violet Typhoon. These actors demonstrate advanced capabilities, including the use of custom webshells, credential theft, lateral movement tools like Impacket, and sophisticated persistence mechanisms.
Organizations are advised to take immediate action to mitigate the risk posed by CVE-2026-50522. This includes applying all available Microsoft SharePoint security updates released in July 2026 or later, rotating ASP.NET machine keys, conducting a thorough audit of SharePoint server directories for unauthorized webshells and malicious DLLs, and restricting external access to SharePoint administrative interfaces.