Collab365 SpacesCollab365 Spaces
SpacesBoardsPricingAcademy membersHow It Works
Collab365 Spaces

AI changes work. Know what to do.

Follow Collab365

FacebookLinkedInInstagramX (Twitter)TikTokYouTube
Excellent on TrustpilotTrustScore 4.5/514 reviews

Platform

  • Explore Spaces
  • Create Account
  • Spaces Roadmap
  • For Teams

Company

  • How We're Surviving AI
  • Blog
  • Academy members
  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Cookie Policy

© 2026 Collab365 Spaces Limited. All rights reserved.

Badhan Ct, Castle St, Hadley, Telford, Shropshire, TF1 5QX, UK

AI changes work. Know what to do.

Hackers exploit critical on-prem SharePoint flaw after public proof of concept

Reviewed by Helen Jones23 JulLast review 23 Jul 2026
Hackers exploit critical on-prem SharePoint flaw after public proof of concept

A critical SharePoint Server bug, CVE-2026-50522, is under active attack after a public proof of concept appeared. The flaw scores 9.8 on the CVSS scale and lets an unauthenticated attacker run code over the network by abusing deserialization of untrusted data. Microsoft patched it in the July 2026 Patch Tuesday release. Security firm watchTowr reports attackers are already using the exploit and stealing machine keys so they can keep access even after the server is updated. It is the third on-premises SharePoint Server vulnerability tied to active exploitation in July 2026, alongside two other flaws. Affected products are SharePoint Server 2016, 2019, and Subscription Edition on builds older than the July updates. SharePoint Online is not affected.

For years, many mid-size Microsoft 365 teams treated on-prem SharePoint as a fading side issue. The real daily pain was Teams sprawl, guest links, and intranet ownership in the cloud. Unpatched server farms sat behind VPN assumptions or old project sites nobody wanted to touch. That posture is now expensive. Unauthenticated remote code execution plus stolen machine keys means a forgotten SharePoint box can become a durable foothold, and simply installing the July cumulative update may not eject an attacker who already harvested keys. Hybrid and leftover on-prem intranet backends suddenly sit on the same urgency list as permission cleanup and Copilot readiness.

Analysis

This is a change to act on if you still run any on-prem SharePoint, not a trend to watch from the sidelines. Inventory every SharePoint Server 2016, 2019, and Subscription Edition host, apply the July 2026 security updates immediately, and if any of those servers were reachable or unpatched after the PoC dropped, rotate the ASP.NET machine keys and recycle the app pools so a stolen key cannot keep the door open.

Read full story on thehackernews.com

Source note

Source note

Pulse published by Collab365 Spaces, reviewed by Helen Jones on 23 Jul 2026. Cite as "Hackers exploit critical on-prem SharePoint flaw after public proof of concept", Collab365 Spaces. 3 sources referenced.

spaces.collab365.com/posts/hackers-exploit-critical-on-prem-sharepoint-flaw-a-brOFBt