Act
archived
Critical SharePoint RCE CVE-2026-50522 Actively Exploited After PoC
- Engineer — Act: CVSS 9.8 deserialization RCE with public PoC and confirmed active exploitation — patch SharePoint Server to the July 2026 Patch Tuesday build immediately; do not wait for CISA KEV confirmation given exploitation is already underway.
- SOC/IR — Act: Active exploitation predating your patch window means assume-breach posture is warranted — hunt for anomalous deserialization or code execution activity on SharePoint servers back to at least the PoC publication date, and review watchTowr’s reporting for any available IOCs or behavioral signatures.
- Leader — Act: A CVSS 9.8 unauthenticated RCE in widely-deployed enterprise SharePoint under active exploitation requires a same-week exposure check — confirm whether the org runs on-premises SharePoint Server and verify the engineering team has prioritized the July Patch Tuesday update.
- Signals: CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.