A new SharePoint vulnerability, CVE-2026-50522, has been found actively exploited in the wild, marking the fourth such exploitation reported in a month. Microsoft released a patch for this critical remote code execution flaw on July 14. Threat intelligence firm Defused identified the first exploitation attempts, which were confirmed by WatchTowr shortly after exploit code was made public. Attackers are reportedly stealing machine keys from SharePoint servers.
CISA has alerted organizations about this vulnerability, while Microsoft has not yet updated its advisory to confirm ongoing exploitation. Other recently reported vulnerabilities include CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.