United States hackers exploit critical SharePoint vulnerability
PUBLISHED Jul 21, 2026, 7:03 PM ET
Read, Watch or Listen
United States – Cybersecurity researchers warned on July 21, 2026, that attackers are actively exploiting a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522. The flaw carries a CVSS score of 9.8 out of 10 and allows unauthenticated attackers to execute arbitrary code over a network, posing an immediate risk to unpatched, on-premises SharePoint deployments across the country. The deserialization-of-untrusted-data vulnerability affects several widely used editions of Microsoft’s collaboration platform, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, making the potential impact broad for organizations that rely on these products for internal document sharing and workflow management. United States – Microsoft disclosed and patched CVE-2026-50522 on July 14, 2026, as part of its monthly Patch Tuesday release, which addressed a record 570 security flaws, and its advisory at the time described exploitation as more likely but not yet observed. The situation changed rapidly on July 20, 2026, when a researcher using the handle Janggggg published a fully functional PowerShell proof-of-concept exploit on GitHub, after which security firms observed immediate exploitation in the wild. The exploit shows how attackers can abuse SharePoint’s token-handling process by delivering a malicious .NET BinaryFormatter payload disguised as a cookie inside a forged SecurityContextToken in a WS-Federation sign-in response, which is then sent to the '/_trust/default.aspx' endpoint, triggering remote code execution when the server deserializes the untrusted data.
By Lauren Mitchell | JQJO News
Timeline of Events
- July 14, 2026 Microsoft releases SharePoint security patch
- July 14, 2026 CVE-2026-50522 details formally disclosed
- Mid-July 2026 organizations begin patch deployment efforts
- July 20, 2026 researcher Janggggg publishes PowerShell exploit
- July 20, 2026 proof-of-concept shared publicly on GitHub
- July 21, 2026 researchers confirm active exploitation campaigns
- July 21, 2026 on-premises SharePoint servers targeted nationwide
News Intelligence
- If your organization uses SharePoint for document sharing, you're at risk. Hackers can use this flaw to take over your system. It's crucial to install the latest security patch ASAP. Check with your IT department today.
Comments