The in-the-wild exploitation of yet another SharePoint vulnerability has come to light – the fourth in the past month.
The flaw is tracked as CVE-2026-50522, and it was fixed by Microsoft on July 14 with its latest Patch Tuesday updates.
Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming from deserialization of untrusted data.
“In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server,” the company wrote in its advisory.
Threat intelligence firm Defused appears to be the first to have observed exploitation of CVE-2026-50522.










