A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused.
The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network.
Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.
The initial disclosure was part of a larger July 14 patch release by Microsoft. The company said exploitation of the flaw would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack.
Researchers at watchTowr warned, however, that patching is not enough to address the deserialization flaw and that security teams “should rotate credentials on any assets that may have been exposed.”
According to watchTowr’s team, the vulnerability is extremely serious, telling Cybersecurity Dive the latest exploit has “ToolShell-class impact.” ToolShell was a summer 2025 campaign by ransomware and state-linked groups where hundreds of SharePoint customers were compromised. Multiple federal agencies were hit in the attacks.
Microsoft released security updates to address CVE-2026-50522 and said customers should upgrade to the latest version, a spokesperson told Cybersecurity Dive. The company is not aware of any exploitation prior to publishing the CVE.
Source: Cybersecurity Dive