A critical SharePoint Server flaw tracked as CVE-2026-50522 is now being actively exploited following the release of a public proof-of-concept, according to BleepingComputer. For UK teams running on-premises SharePoint, the window between patch release and compromise has effectively closed.
View the data behind this chart
| Phase | Starts (week) | Duration (weeks) |
|---|---|---|
| CVE-2026-56164 exploited as… | 0 | 1 |
| CVE-2026-58644 exploited as… | 1 | 1 |
| CVE-2026-50522 exploited… | 2 | 2 |
What Microsoft disclosed and what changed
Microsoft shipped a fix for CVE-2026-50522 as part of its July 2026 Patch Tuesday, rating the SharePoint Server flaw critical with a CVSS score of 9.8. The root cause is deserialization of untrusted data in Microsoft Office SharePoint, which allows an unauthenticated attacker to execute code over the network without needing valid credentials.
Microsoft's own advisory tags the flaw "Exploitation More Likely" — but that assessment has already been overtaken by events. Security firm watchTowr says it detected active exploitation against on-premises SharePoint deployments once a public proof-of-concept exploit began circulating, turning a theoretical risk into a live incident-response scenario for anyone still running unpatched servers.
Why this is the third SharePoint fire this month
CVE-2026-50522 is not an isolated event. BleepingComputer places it as the third SharePoint Server vulnerability exploited in the wild during the July 2026 wave, following CVE-2026-56164 and CVE-2026-58644, both weaponised as zero-days before Microsoft patched them. CISA has separately flagged CVE-2026-32201, CVE-2026-45659 and CVE-2026-56164 as actively exploited against on-premises SharePoint Server instances, and Computer Weekly reported CISA adding CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue.
For buyers, the pattern matters more than any single CVE: SharePoint on-premises has become a recurring, repeat target rather than a one-off scare. Organisations still weighing whether to migrate off legacy on-prem farms should treat this cluster as a strong signal that vulnerability management strategies need to assume continuous SharePoint risk, not episodic patching.
Scope: which SharePoint versions are exposed
CISA's warning is explicit that the vulnerabilities affect all supported on-premises SharePoint Server versions, including Subscription Edition, 2019 and 2016. This is a broad footprint across UK public sector, higher education and enterprise deployments that have kept SharePoint on-premises for compliance, customisation or licensing reasons rather than moving fully to SharePoint Online within Microsoft 365.
Cloud-only Microsoft 365 tenants are not the target here — the exploitation activity described in the brief is specific to on-premises deployments. That distinction should shape where security budget goes next: on-prem SharePoint estates need urgent attention, while wider Office 365 admin hygiene remains a separate but related priority.

The real danger: machine key theft and persistence
The most consequential detail for incident responders is what happens after initial compromise. watchTowr and CISA both describe attackers stealing IIS machine keys during exploitation, which lets them forge authentication and maintain persistent access even after a server is patched. CISA's advisory states the vulnerabilities involve remote code execution and post-exploitation activity such as stealing IIS machine keys and using deserialization to gain persistence and deploy malware.
This means patching alone does not remediate a compromised host. If machine keys were stolen before the patch was applied, an attacker can potentially continue operating on a server that Microsoft's July update has otherwise closed. This is precisely the scenario effective incident response plans need to account for: patch, then hunt, then rotate keys — in that order, not patch alone.
Patch prioritisation and a post-compromise checklist
Given the CVSS 9.8 rating and confirmed active exploitation, CVE-2026-50522 should sit at the top of any UK organisation's patch queue this cycle, ahead of lower-severity items in Microsoft's record 622-CVE July release. Teams juggling that volume need a risk-based approach — this is exactly the kind of decision that understanding patch management priorities is built for, distinguishing genuinely exploited flaws from routine updates.
Beyond patching, BleepingComputer's related SharePoint zero-day coverage recommends checking for indicators of compromise including the creation of a file named spinstall0.aspx and suspicious IIS log requests to ToolPane.aspx. Administrators who find either indicator should assume the server is compromised and take it offline rather than relying on the patch alone. Rotating IIS machine keys, reviewing SharePoint audit logs for anomalous activity, and validating backups through robust backup and disaster recovery processes should all follow immediately.
UK compliance and board-level implications
For regulated UK organisations, an actively exploited critical RCE with confirmed persistence mechanisms is a reportable-risk event, not a routine patch note. Boards and DPOs should expect questions about whether SharePoint content — often holding personal data, contracts and internal correspondence — was accessible during the exploitation window, and whether machine key theft occurred before remediation.
Given the breadth of this SharePoint exploitation wave sitting alongside a record-setting Patch Tuesday, this is a reasonable moment to stress-test wider defences: reviewing zero trust segmentation around on-prem SharePoint farms, confirming managed detection & response coverage extends to IIS and SharePoint logs, and checking that Microsoft 365 backup solutions are in place for hybrid environments where on-prem and cloud content coexist.
- 01BleepingComputer — Critical SharePoint RCE CVE-2026-50522 under active exploitation after public PoC · 21 July 2026
- 02The Hacker News — Critical SharePoint RCE CVE-2026-50522 · 21 July 2026
- 03The Hacker News — Microsoft patches record 622 flaws · 8 July 2026
- 04BleepingComputer — CISA warns admins to patch actively exploited SharePoint flaws · 15 July 2026
- 05BleepingComputer — Microsoft SharePoint zero-day exploited in RCE attacks · 10 July 2026
- 06Computer Weekly — US cyber agency warns over forgotten SharePoint flaw · 16 July 2026
