Hackers exploit critical on-prem SharePoint flaw after public proof of concept

A critical SharePoint Server bug, CVE-2026-50522, is under active attack after a public proof of concept appeared. The flaw scores 9.8 on the CVSS scale and lets an unauthenticated attacker run code over the network by abusing deserialization of untrusted data. Microsoft patched it in the July 2026 Patch Tuesday release. Security firm watchTowr reports attackers are already using the exploit and stealing machine keys so they can keep access even after the server is updated. It is the third on-premises SharePoint Server vulnerability tied to active exploitation in July 2026, alongside two other flaws. Affected products are SharePoint Server 2016, 2019, and Subscription Edition on builds older than the July updates. SharePoint Online is not affected.
For years, many mid-size Microsoft 365 teams treated on-prem SharePoint as a fading side issue. The real daily pain was Teams sprawl, guest links, and intranet ownership in the cloud. Unpatched server farms sat behind VPN assumptions or old project sites nobody wanted to touch. That posture is now expensive. Unauthenticated remote code execution plus stolen machine keys means a forgotten SharePoint box can become a durable foothold, and simply installing the July cumulative update may not eject an attacker who already harvested keys. Hybrid and leftover on-prem intranet backends suddenly sit on the same urgency list as permission cleanup and Copilot readiness.
Analysis
This is a change to act on if you still run any on-prem SharePoint, not a trend to watch from the sidelines. Inventory every SharePoint Server 2016, 2019, and Subscription Edition host, apply the July 2026 security updates immediately, and if any of those servers were reachable or unpatched after the PoC dropped, rotate the ASP.NET machine keys and recycle the app pools so a stolen key cannot keep the door open.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Hackers exploit critical on-prem SharePoint flaw after public proof of concept", Collab365 Spaces. 3 sources referenced.