hacker-news · Crawled Jul 21, 2026
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Read original article ↗AI Summary
A critical remote code execution vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-50522, is under active exploitation following the release of a public proof-of-concept. The flaw allows unauthenticated attackers with at least Site Owner privileges to execute arbitrary code and steal IIS machine keys for persistent access. Security agencies and researchers emphasize immediate patching and credential rotation to mitigate ongoing threats.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.