Find notable cyber news and cases, enriched with sources, timelines, and signals.

SharePoint exploitation wave

Exploitation Wave
First reported
Last updated
Happening score
H score 42
1 unique sources, 1 articles

Summary

Hide ▲

In-the-wild exploitation of SharePoint flaws has expanded to a fourth case in the past month, increasing the risk to exposed SharePoint instances.

Related Happenings

Microsoft SharePoint Server deserialization RCE (CVE-2026-50522, actively exploited)

Vulnerability
H score53 First: 21.07.2026 17:57 Last: 21.07.2026 17:57 Sources 1

How related: The flaw is tracked as CVE-2026-50522, and it was fixed by Microsoft on July 14 with its latest Patch Tuesday updates.

About this happening: CVE-2026-50522 puts on-premises Microsoft SharePoint Server deployments at risk of critical remote code execution, and active exploitation after a public PoC enabl...

Latest development: 22.07.2026 03:00

Microsoft fixed CVE-2026-50522 in its July 14 Patch Tuesday updates. Microsoft describes the SharePoint Server flaw as a critical remote code execution vulnerability stemming from deserialization of untrusted data, and says an attacker authenticated as at least a Site Owner could write arbitrary code and execute it remotely.

SharePoint Server unauthenticated privilege escalation flaw actively exploited (CVE-2026-56164)

Vulnerability
H score82 First: 14.07.2026 23:25 Last: 14.07.2026 23:25 Sources 1

About this happening: CVE-2026-56164 is an actively exploited SharePoint Server vulnerability that lets an unauthenticated attacker escalate privileges over the network. The flaw puts *...

Latest development: 15.07.2026 12:20

Microsoft’s July 14 Patch Tuesday included CVE-2026-56164, an elevation-of-privilege flaw in Microsoft SharePoint Server that required no existing privileges and was described as low complexity. The zero-day was one of two vulnerabilities in the release that had been exploited in the wild, and Microsoft issued updates for affected systems.

Magento exploitation wave for CVE-2026-45247

Exploitation Wave
H score9 First: 04.06.2026 10:19 Last: 04.06.2026 10:19 Sources 1

About this happening: Active exploitation of CVE-2026-45247 is hitting Mirasvit Cache Warmer on Magento stores, with malicious requests carrying serialized PHP payloads that can lead to r...

FamousSparrow multi-wave intrusion campaign against Azerbaijani oil and gas company

Campaign
H score39 First: 13.05.2026 16:00 Last: 13.05.2026 16:00 Sources 1

About this happening: A China-affiliated actor tracked as FamousSparrow (UAT-9244) ran a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 202...

Microsoft April 2026 Patch Tuesday security update (165 CVEs)

Security Patch Release
H score62 First: 15.04.2026 00:22 Last: 15.04.2026 00:22 Sources 1

About this happening: Microsoft shipped April 2026 Patch Tuesday updates covering 165 CVEs, including an actively exploited zero-day and a publicly disclosed flaw, creating immediat...

Timeline

  1. 22.07.2026 14:29 1 articles · 1h ago

    Defused honeypots see exploitation attempts against a suspected zero-day SharePoint vulnerability

    Detection Ioc Update

    Defused reported on July 17 that its honeypots had seen exploitation attempts against what appeared to be a zero-day SharePoint vulnerability.

    Show sources
  2. 22.07.2026 14:29 1 articles · 1h ago

    WatchTowr confirms active exploitation and SharePoint machine-key theft

    Exploitation Observed

    One day later, shortly after PoC exploit code was released, WatchTowr confirmed active exploitation of CVE-2026-50522 and said attackers were pulling SharePoint machine keys via a single request to retain long-term access.

    Show sources
  3. 22.07.2026 14:29 2 articles · 1h ago

    CISA warns organizations about attacks targeting SharePoint instances

    Industry Or Public Sector Update

    CISA warned organizations about attacks targeting SharePoint instances, and CVE-2026-50522 had not yet been added to the Known Exploited Vulnerabilities catalog.

    Show sources