United States – Cybersecurity researchers warned on July 21, 2026, that attackers are actively exploiting a critical remote code execution vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522. The flaw carries a CVSS score of 9.8 out of 10 and allows unauthenticated attackers to execute arbitrary code over a network, posing an immediate risk to unpatched, on-premises SharePoint deployments across the country. The deserialization-of-untrusted-data vulnerability affects several widely used editions of Microsoft’s collaboration platform, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, making the potential impact broad for organizations that rely on these products for internal document sharing and workflow management. United States – Microsoft disclosed and patched CVE-2026-50522 on July 14, 2026, as part of its monthly Patch Tuesday release, which addressed a record 570 security flaws, and its advisory at the time described exploitation as more likely but not yet observed. The situation changed rapidly on July 20, 2026, when a researcher using the handle Janggggg published a fully functional PowerShell proof-of-concept exploit on GitHub, after which security firms observed immediate exploitation in the wild. The exploit shows how attackers can abuse SharePoint’s token-handling process by delivering a malicious .NET BinaryFormatter payload disguised as a cookie inside a forged SecurityContextToken in a WS-Federation sign-in response, which is then sent to the '/_trust/default.aspx' endpoint, triggering remote code execution when the server deserializes the untrusted data.
Prepared by Jonathan Pierce and reviewed by editorial team.
No left-leaning sources found for this story.
No right-leaning sources found for this story.
Comments