THREATOPS
THREAT OPSThreat News › 2026-009: Critical Vulnerabilities in Microsoft SharePoint

2026-009: Critical Vulnerabilities in Microsoft SharePoint

lowcert_euPublished 2026-07-23

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Serv

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://cert.europa.eu/publications/security-advisories/2026-009/