Fourth SharePoint Vulnerability Exploited Amid Recent Cyber Attacks
A new SharePoint vulnerability, CVE-2026-50522, has been exploited in the wild, marking the fourth such incident in the past month. This critical remote code execution vulnerability, which stems from the deserialization of untrusted data, was patched by Microsoft on July 14. Despite the patch, threat actors have been actively exploiting the flaw, with reports indicating that attackers are stealing machine keys to maintain long-term access to compromised systems. Security firm WatchTowr confirmed the active exploitation following the release of proof-of-concept exploit code. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has previously warned organizations about attacks targeting SharePoint instances, highlighting the ongoing threat posed by these vulnerabilities.