watchTowr said attackers are now actively exploiting CVE-2026-50522 against on-premises SharePoint, using a public proof-of-concept to pull machine keys in a single request and keep persistent access.
The flaw carries a 9.8 CVSS score and lets remote attackers execute code; Microsoft said exploitation was more likely, though its advisory described the bug as requiring Site Owner-level authentication.
Defused Cyber said captured requests to a SharePoint sign-in endpoint contained no authentication material, suggesting threat actors are delivering a .NET deserialization payload through an unauthenticated path.
CVE-2026-50522 is the third July-patched SharePoint bug to see active abuse after CVE-2026-56164 and CVE-2026-58644, both exploited as zero-days before fixes.
CISA has warned multiple SharePoint flaws are being chained across supported on-premises versions—Subscription Edition, 2019 and 2016—for RCE, IIS key theft, persistence and malware deployment.