SharePoint Vulnerability CVE-2026-50522 Exploited Globally
A critical vulnerability in Microsoft SharePoint has been exploited by sophisticated threat actors, resulting in significant breaches and ransomware deployments. The CVE-2026-50522 flaw enables remote code execution via deserialization of untrusted data and affects all supported on-premises versions of Microsoft SharePoint Server.
Attackers are leveraging this weakness to gain unauthorized access, steal sensitive credentials, deploy webshells, and establish persistent footholds within enterprise environments. Both state-sponsored advanced persistent threat groups and financially motivated cybercriminals have targeted vulnerable organizations globally.
The exploitation is low in complexity, can be automated, and has already resulted in widespread data breaches and operational disruptions. Organizations operating on-premises Microsoft SharePoint Server instances that are exposed to the internet and have not applied the latest security patches are most at risk.