CVE-2026-50522: Microsoft Addresses Critical Remote Code Execution Vulnerability in SharePoint Server with Security Update

Published:

spot_img

Microsoft has issued a security update addressing CVE-2026-50522, a critical remote code execution vulnerability in on-premises SharePoint Server. This vulnerability allows an authenticated site owner to execute arbitrary code and potentially steal machine keys for persistent access. Active exploitation has been reported following the release of proof-of-concept code. Organizations using SharePoint Server are urged to apply the security update immediately to mitigate risks.

What the Advisory Covers

This advisory details a significant vulnerability in Microsoft SharePoint Server that could lead to unauthorized code execution. The flaw is particularly concerning as it can be exploited by authenticated users, making it critical for organizations to address it promptly.

Affected Products and Versions

  • Microsoft SharePoint Server (on-premises)

Severity and Exploitation Status

The vulnerability is classified as critical, with reports of active exploitation following the availability of proof-of-concept code. Organizations should prioritize remediation efforts to protect their systems.

Available Patches or Fixed Versions

Microsoft has released a security update to address CVE-2026-50522. Organizations are encouraged to apply this update as soon as possible to mitigate the risk associated with this vulnerability.

Recommended Actions

  • Apply the security update for SharePoint Server immediately.
  • Review user permissions to limit access to authenticated site owners where possible.
  • Monitor for unusual activity that may indicate exploitation attempts.

For further details, refer to the Check Point Research advisory.

spot_img

Related articles

Recent articles

Atlassian Rovo Vulnerability Allows Data Exfiltration from Jira and Confluence

Recent findings have revealed a vulnerability in Atlassian's Rovo assistant that allows attacker-controlled instructions to extract data from Jira and Confluence. This issue was...

Qilin Ransomware Claim: Stade Français Investigates Data Leak After Cyberattack

Qilin Ransomware Claim: Stade Français Paris has confirmed it was targeted by a cyberattack that disrupted its information systems. The club reported that it...

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists

Georgia Investigates Alleged Foreign Disinformation Campaign Targeting Russian Tourists. The State Security Service of Georgia has initiated a criminal investigation into a purported disinformation...

Untrusted Data Safety

Microsoft Defender’s attack disruption now includes device isolation, a new response action that enhances protection for compromised endpoints. This capability was recently highlighted in...