Microsoft SharePoint under attack via new exploit | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused

The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network. 

Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.

The initial disclosure was part of a larger July 14 patch release by Microsoft. The company said exploitation of the flaw would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack. 

Researchers at watchTowr warned, however, that patching is not enough to address the deserialization flaw and that security teams “should rotate credentials on any assets that may have been exposed.” 

According to watchTowr’s team, the vulnerability is extremely serious, telling Cybersecurity Dive the latest exploit has “ToolShell-class impact.” ToolShell was a summer 2025 campaign by ransomware and state-linked groups where hundreds of SharePoint customers were compromised. Multiple federal agencies were hit in the attacks.

Microsoft released security updates to address CVE-2026-50522 and said customers should upgrade to the latest version, a spokesperson told Cybersecurity Dive. The company is not aware of any exploitation prior to publishing the CVE.

“The security update fully mitigates the issue, however rotating machine keys can be performed to further safeguard user environments,” the spokesperson said. 

CISA alert

Just one week ago, the Cybersecurity and Infrastructure Security Agency warned of three vulnerabilities in SharePoint facing exploitation: 

  • An improper input validation vulnerability, tracked as CVE-2026-32201, allows an attacker to perform spoofing over a network. 
  • A remote code execution vulnerability, tracked as CVE-2026-45659, involves deserialization of untrusted data.
  • The third vulnerability, CVE-2026-56164, allows an attacker to elevate privileges over a network. According to ShadowServer Foundation, more than 1,000 instances are exposed, with about half of them located in North America. 

Editor’s note: Updated with comments from Microsoft. 



——————————————————-


Click Here For The Original Source.

National Cyber Security

FREE
VIEW