Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)

Vulnerability
First reported
Last updated
Happening score
H score 46
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enables attackers to steal machine keys for persistence.

Related Happenings

Storm-1175 high-tempo Medusa ransomware campaign

Campaign
H score59 First: 07.04.2026 13:02 Last: 07.04.2026 13:02 Sources 1

About this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...

Storm-1175 high-velocity zero-day and N-day intrusion campaign

Campaign
H score44 First: 07.04.2026 09:35 Last: 07.04.2026 09:35 Sources 1

About this happening: Storm-1175 is running a high-velocity intrusion campaign that chains zero-day and N-day vulnerabilities to gain initial access to exposed systems, raising the risk...

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
H score38 First: 17.03.2026 17:36 Last: 17.03.2026 17:36 Sources 1

About this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...

UnsolicitedBooker Central Asian telecom phishing campaign

Campaign
H score31 First: 24.02.2026 11:54 Last: 24.02.2026 11:54 Sources 1

About this happening: The UnsolicitedBooker cluster shifted its phishing operation to telecommunications companies in Kyrgyzstan and Tajikistan, extending a multi-month campaign that matters be...

CISA KEV mitigation for BeyondTrust CVE-2026-1731

Advisory/Mitigation
H score46 First: 20.02.2026 19:02 Last: 20.02.2026 19:02 Sources 1

About this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...

Timeline

  1. 21.07.2026 17:57 2 articles · 3h ago

    watchTowr reports active exploitation of CVE-2026-50522 in SharePoint Server

    Initial Disclosure

    Microsoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday update, and watchTowr said it detected active exploitation against on-premises Microsoft SharePoint deployments after a public proof-of-concept exploit. The flaw is a critical deserialization issue in Microsoft Office SharePoint that can allow remote code execution, and attackers are said to be stealing machine keys to maintain persistent access; CISA also warned that multiple SharePoint Server vulnerabilities are being exploited to gain unauthorized access to on-premises instances.

    Show sources