HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical SharePoint RCE (CVE‑2026‑50522) Actively Exploited via Public PoC

A critical deserialization flaw in Microsoft SharePoint (CVE‑2026‑50522) was patched in July 2026, but a public PoC released on July 20 has already been observed in the wild. Organizations must patch, rotate machine keys, and capture remediation evidence to stay audit‑ready under SOC 2.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
securityaffairs.com

Critical SharePoint Remote Code Execution (CVE‑2026‑50522) — Public PoC Triggers Active Exploitation

What It Is — A deserialization flaw in Microsoft SharePoint (CVE‑2026‑50522) allows an attacker to execute arbitrary code on vulnerable on‑premises servers. The vulnerability was patched in Microsoft’s July 2026 Patch Tuesday but a public proof‑of‑concept (PoC) was released on July 20, 2026 and is now being used in the wild.

Exploitability — CVSS 9.8 (Critical). Public PoC available; watchTowr’s honeypot network recorded successful exploitation within hours of release.

Affected Products — Microsoft SharePoint Server (on‑premises) versions prior to the July 2026 security update.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping & Continuous Evidence – SOC 2 Change Management (CC6.1) requires documented, timely patching; automated mapping of patch status to this control provides audit‑ready evidence.
  • Credential Hygiene & Key Rotation – The exploit steals SharePoint machine keys; SOC 2 Access Control (CC6.2) expects rotation of compromised secrets and proof of remediation.
  • Defensible Incident Response – Demonstrating rapid detection, containment, and evidence collection satisfies SOC 2 Incident Management (CC7.1) and reduces audit‑panel risk.

Recommended Actions

  • Deploy Microsoft’s July 2026 Patch Tuesday update to all SharePoint servers immediately.
  • Verify patch deployment with an automated inventory tool and capture screenshots or logs as SOC 2 evidence.
  • Rotate SharePoint machine keys and any credentials that may have been exposed; document the rotation process.
  • Update your SOC 2 change‑management and access‑control documentation to reflect the remediation steps.

Source: Security Affairs – Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE‑2026‑50522

📰 Original Source
https://securityaffairs.com/195760/security/public-poc-triggers-active-exploitation-of-critical-sharepoint-rce-vulnerability-cve-2026-50522.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →