Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.

The flaw is tracked as CVE-2026-50522, and it was fixed by Microsoft on July 14 with its latest Patch Tuesday updates.

Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming from deserialization of untrusted data.

“In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server,” the company wrote in its advisory.

Threat intelligence firm Defused appears to be the first to have observed exploitation of CVE-2026-50522.

The company reported on July 17 that its honeypots had seen exploitation attempts targeting what appeared to be a zero-day SharePoint vulnerability. However, in an update shared on July 20, Defused said the targeted vulnerability was likely CVE-2026-50522.

Advertisement. Scroll to continue reading.

One day...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more