Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enables attackers to steal machine keys for persistence.
Related Happenings
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
Campaign
H score44
First: 07.04.2026 09:35
Last: 07.04.2026 09:35
Sources 1
About this happening:
Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Storm-1175 high-velocity zero-day and N-day intrusion campaign
CampaignAbout this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...
Warlock ransomware post-exploitation tooling upgrades
Malware Activity
H score38
First: 17.03.2026 17:36
Last: 17.03.2026 17:36
Sources 1
About this happening:
The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
Warlock ransomware post-exploitation tooling upgrades
Malware ActivityAbout this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...
UnsolicitedBooker Central Asian telecom phishing campaign
Campaign
H score31
First: 24.02.2026 11:54
Last: 24.02.2026 11:54
Sources 1
About this happening:
The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
UnsolicitedBooker Central Asian telecom phishing campaign
CampaignAbout this happening: The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
Timeline
-
21.07.2026 17:57 2 articles · 3h ago
watchTowr reports active exploitation of CVE-2026-50522 in SharePoint Server
Initial DisclosureMicrosoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday update, and watchTowr said it detected active exploitation against on-premises Microsoft SharePoint deployments after a public proof-of-concept exploit. The flaw is a critical deserialization issue in Microsoft Office SharePoint that can allow remote code execution, and attackers are said to be stealing machine keys to maintain persistent access; CISA also warned that multiple SharePoint Server vulnerabilities are being exploited to gain unauthorized access to on-premises instances.
Show sources
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — thehackernews.com — 21.07.2026 17:57
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC — thehackernews.com — 21.07.2026 17:57