Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek.
The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.
The flaw is tracked as CVE-2026-50522, and it was fixed by Microsoft on July 14 with its latest Patch Tuesday updates.
Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming from deserialization of untrusted data.
Related breach coverage
- New Check Point Zero-Day Vulnerability Exploited in the Wild2026-07-23
The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.
- Exploitation of ServiceNow Vulnerability Seen Days After Disclosure2026-07-21
The ServiceNow AI platform vulnerability tracked as CVE-2026-6875 can be exploited for remote code execution. The post Exploitation of ServiceNow Vulnerability Seen Days After Disclosure appeared first on SecurityWeek.
- SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch2026-07-20
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533. The post SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch appeared first on SecurityWeek.
- Fresh SharePoint Vulnerability Exploited Soon After Disclosure2026-07-17
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server. The post Fresh SharePoint Vulnerability Exploited Soon After Disclosure appeared first on SecurityWeek.
