Microsoft Warns Critical SharePoint Flaw Is Under Active Attack

https://hothardware.com/contentimages/NewsItem/71195/content/16x9_2133x1200_highres-ms-sharepoint.jpg

Another new vulnerability for Microsoft SharePoint, tracked as CVE-2026-50522, is now being actively exploited in the wild, Microsoft warns. Security team watchTowr found evidence of exploits in use, and noted that attacks started the same day, July 20th, as when a Proof of Concept (PoC) attack was published. Another security company, Defused, detected attacks as early as July 17th, which points to private versions of the attack developed in parallel rather than the published PoC version of the attack.

The eagle-eyed among you may notice that the vulnerability tracked as CVE-2026-50522 is one of the problems fixed in July's Patch Tuesdayfor Windows 11. At the time, no evidence of the vulnerability in use existed, but in the time since, attackers are using it as a vector against organizations that have yet to apply patches and secure SharePoint. Now that black hats are actively leveraging the vulnerability, applying the...

Copyright of this story solely belongs to hothardware.com. To see the full text click HERE

Read more