Skip to main content

CVE detail

CVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 9.8 · CriticalBuzz score 75.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 75.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
54 evidence mentions in the snapshot
Diversity score
20.0
14 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
54
within the 30d window
Peak daily
10
highest bucket

Evidence

Source links by recency

Newest mentions first
54 source links · newest first
  • with the attacks starting shortly after the release of a proof-of-concept (PoC) exploit. The vulnerability, tracked as CVE-2026-55040, was fixed by Microsoft with its July Patch Tuesday updates. Microsoft described it as a weak authentication issue that allows an attacker to bypass a security feature over a network. “Exploiting this vulnerability coul

    newswww.securityweek.comAug 12, 2026, 2:47 PM
  • payment information was accessed. Exactly three years ago, Metabase moved to address another "extremely severe" flaw ( CVE-2023-38646 , CVSS score: 9.8) that could have resulted in pre-authenticated remote code execution on affected installations. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive co

    newsthehackernews.comAug 8, 2026, 6:58 AM
  • in the SharePoint software.” However, it has not disclosed which flaw was used. The attack potentially involved either CVE-2026-56164, an actively exploited SharePoint privilege escalation vulnerability, or CVE-2026-50522, a remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched. BIT

    newswww.helpnetsecurity.comAug 7, 2026, 12:29 PM
  • synchronization zero-day in Apache Traffic Server. The researchers said the issue has since been patched and tracked as CVE-2026-63078. An August 7 check by The Hacker News did not find a public record for CVE-2026-63078 in CVE.org or NVD, and Apache's July advisory covering 34 flaws did not list it. That leaves a verification gap around the Apache cas

    newsthehackernews.comAug 7, 2026, 10:09 AM
  • updates from July, you should focus on getting the SharePoint patches out. The Microsoft Security Center announced that CVE-2026-50522, a remote code execution vulnerability, is now actively being exploited . Hackers can steal machine keys using this vulnerability and maintain access after the system is patched. With these keys, a remote attacker can e

    newswww.helpnetsecurity.comAug 7, 2026, 6:00 AM
  • e July Patch Tuesday updates. However, it has not disclosed which flaw was used. The attack potentially involved either CVE-2026-56164 , an actively exploited SharePoint privilege escalation vulnerability, or CVE-2026-50522 , a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were pa

    newswww.bleepingcomputer.comAug 6, 2026, 6:14 PM
  • the necessary updates for optimal protection. The vulnerabilities impacting Catalyst SD-WAN Software are listed below - CVE-2026-20303 (CVSS score: 9.9) - An improper input validation vulnerability (which also covers path traversals) CVE-2026-20304 (CVSS score: 9.9) - An improper access control vulnerability CVE-2026-20310 (CVSS score: 9.9) - An improp

    newsthehackernews.comAug 6, 2026, 5:13 PM
  • " One-click device compromise Hacking Into Samsung's Mobile Devices A set of vulnerabilities affecting Samsung devices (CVE-2025-21079 and CVE-2025-58486) could be chained to result in remote system-level compromise triggered by clicking on a link delivered via an ad or a messaging application. "What distinguishes this entry from previous submissions i

    newsthehackernews.comAug 6, 2026, 3:24 PM
  • This Week ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Nine-Year-Old Ref

    newsthehackernews.comAug 6, 2026, 11:30 AM
  • in a security bulletin published August 4 . Two are critical. Veeam released the build on July 29. The one to watch is CVE-2026-58073 (CVSS score: 9.5), which lets an unauthenticated attacker impersonate a managed agent and obtain that agent's credentials. Its CVSS vector rates attack complexity as high. The second critical flaw, CVE-2026-58072 (CVSS

    newsthehackernews.comAug 5, 2026, 2:27 PM
  • nt CVEs allowed attackers to escape execution sandboxes and gain arbitrary read or write access to the host filesystem. CVE-2025-68613 , an expression injection vulnerability with a CVSS score of 9.9, was added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog on March 11, 2026, confirming exploitati

    newsthehackernews.comAug 5, 2026, 10:35 AM
  • y timing matters here. Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14. One flaw, tracked as CVE-2026-50522 (CVSS score of 9.8) could enable an attacker to execute remote code over a network. Microsoft said exploitation would be considered low complexity, as an attacker does not require a great deal of knowledge of the system

    newssecurityaffairs.comAug 4, 2026, 8:12 PM
  • in Mail Logs Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Kimi K3 Agents Found Redis Z

    newsthehackernews.comAug 3, 2026, 10:49 AM
  • the "trust_remote_code" security gate configured to run only against the first. The vulnerabilities are listed below - CVE-2026-44827 (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name "None.py" despite passing tr

    newsthehackernews.comAug 3, 2026, 6:40 AM
  • 25. One such vulnerability discovered in the Chrome codebase is a critical sandbox escape in the Navigation component ( CVE-2026-3545 , CVSS score: 9.6) that could be exploited to trick the browser into reading local files from the user's system. It was patched by Google earlier this March. The shortcoming, per Google, was discovered via an agent harn

    newsthehackernews.comJul 31, 2026, 12:51 PM
  • covered on two real-world commercial 5G core networks. One vendor, Dotouch, has since addressed the defect in XproUPF ( CVE-2026-8233 , CVSS score: 4.6). The second commercial 5GC vendor, an unnamed major 5G carrier, is still in the remediation process. It's worth noting that both CVE-2026-8233 and CVE-2026-36884, which affects OpenAirInterface UPF, d

    newsthehackernews.comJul 31, 2026, 11:55 AM
  • rrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions

    newsthehackernews.comJul 30, 2026, 3:25 PM
  • esktop Installs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Load More ▼ ⭐ Featured Resources Get the Checklist for Gaining Control of AI Use Across Your Organization [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions

    newsthehackernews.comJul 30, 2026, 1:34 PM
  • s June 1 notice does not list a CVE identifier for the AnySign4PC flaw. As of July 30, 2026, The Hacker News found only CVE-2020-7882 in public CVE Program and NVD searches for AnySign4PC, an unrelated directory-traversal vulnerability affecting older versions. That result does not rule out a reserved, unpublished, or differently described identifier.

    newsthehackernews.comJul 30, 2026, 10:33 AM
  • inancial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. Enterprise security company Proofpoint has attributed the ac

    newsthehackernews.comJul 30, 2026, 7:40 AM
  • Web Data Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

    newsthehackernews.comJul 29, 2026, 12:15 PM
  • correspond to the vulnerabilities used during the evaluation. Among the vulnerabilities fixed in Artifactory 7.161.15, CVE-2026-65617, CVE-2026-65923, and CVE-2026-66018 credit OpenAI researchers. The records do not map any CVE to the incident, identify the access required before exploitation, or explain why OpenAI refers to one proxy zero-day while J

    newsthehackernews.comJul 28, 2026, 1:33 PM
  • Web Data Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Load More ▼ ⭐ Featured Resources Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 How to Find and Control Every Script Running Through Your Marketing St

    newsthehackernews.comJul 28, 2026, 6:07 AM
  • 27th July – Threat Intelligence ReportCheck Point Research

    ,000 artifacts and a campaign that recorded over 77,000 requests. VULNERABILITIES AND PATCHES Check Point has addressed CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that is under active exploitation, affecting a handful of customers. The flaw allows remote attackers to bypass authentication and gain administrative access to Ch

    vendorresearch.checkpoint.comJul 27, 2026, 4:00 PM
  • the flaw. SSD did not report active exploitation. As of July 27, 2026, no source had confirmed in-the-wild attacks, and CVE-2026-61511 was not listed in CISA's Known Exploited Vulnerabilities catalog. The company published an interactive proof-of-concept, but the script as posted contains a one-character error, a letter where a digit belongs, that stop

    newsthehackernews.comJul 27, 2026, 2:40 PM
  • products, including a critical flaw that has come under active exploitation in the wild. The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful

    newsthehackernews.comJul 27, 2026, 2:10 PM
  • lized AI Model for Vulnerability Hunting Check Point patches actively exploited SmartConsole authentication bypass flaw CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities cata

    newssecurityaffairs.comJul 26, 2026, 11:42 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 25, 2026, 8:11 PM
  • ktop Installs Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Open-Source Andr

    newsthehackernews.comJul 25, 2026, 10:14 AM
  • aign include manufacturing, automotive, aerospace, and retail sectors. It's suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month. In an advis

    newsthehackernews.comJul 25, 2026, 10:14 AM
  • t secret through DCSync . Microsoft patched the Active Directory Certificate Services (AD CS) issue ten days earlier as CVE-2026-54121 . Microsoft classed the flaw as improper authorization and assigned it a CVSS score of 8.8. Exploitation requires network access and a domain account, but no administrator rights or user interaction. In the researchers'

    newsthehackernews.comJul 24, 2026, 2:15 PM
  • to conduct attacks against third-parties and power their own offensive operations . These efforts involve the abuse of CVE-2024-6587 , CVE-2026-40217 , and CVE-2026-35029. "Self-hosted model servers and agent frameworks keep getting deployed while being misconfigured and unauthenticated, on predictable ports, willing to serve any client," Zenity said

    newsthehackernews.comJul 24, 2026, 11:53 AM
  • nd WordPress flaws to its Known Exploited Vulnerabilities (KEV) catalog . Below are the flaws added to the KeV catalog: CVE-2026-16232 (CVSS score of 9.3) Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 (CVSS score of 9.8) Microsoft SharePoint Deserialization of Untrusted Data Vulnerability The first flaw added to the KeV

    newssecurityaffairs.comJul 23, 2026, 8:10 PM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 23, 2026, 11:44 AM
  • wo new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability These types of vulnerabilities are a frequent attack vector for maliciou

    governmentwww.cisa.govJul 22, 2026, 12:00 PM
  • Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers s

    newswww.helpnetsecurity.comJul 22, 2026, 11:47 AM
  • CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .

    newswww.securityweek.comJul 22, 2026, 11:29 AM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 22, 2026, 8:51 AM
  • Critical SharePoint RCE vulnerability CVE-2026-50522 is under active exploitation after the release of a PoC exploit code. A critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522 (CVSS score of 9.8), is being actively exploited following the release of a

    newssecurityaffairs.comJul 21, 2026, 9:38 PM
  • Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]

    newswww.bleepingcomputer.comJul 21, 2026, 8:06 PM
  • d AI Model for Vulnerability Hunting | Check Point patches actively exploited SmartConsole authentication bypass flaw | CVE-2026-8933: Ubuntu security flaw breaks Snap sandbox protections | Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft | U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities

    newssecurityaffairs.comJul 21, 2026, 6:25 PM
  • Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE

    newsthehackernews.comJul 21, 2026, 2:57 PM
  • t families affected by July 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Active Directory Federation Services CVE-2026-56155 is an Important elevation of privilege vulnerability affecting Active Directory Federation Services (AD FS) and has a CVSS score of 7.8 . An insufficient granularity of access control flaw (CWE-1220) allows a low-privil

    vendorwww.crowdstrike.comJul 17, 2026, 8:00 PM
  • Overview On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644 , a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments. The vulnerability, which carries a CVSS v3.1 score of 9.8 (Critical), results from the deserializatio

    vendorwww.rapid7.comJul 17, 2026, 6:18 PM
  • ation of remediations as a trailing indicator. SharePoint: critical auth bypass by Rapid7 Today sees the publication of CVE-2026-55040 , a critical authentication bypass in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft, this vulnerability is the first i

    vendorwww.rapid7.comJul 14, 2026, 10:00 PM
  • this mess is anyone’s guess.” states the report published by ZDI. The following two bugs are being actively exploited: CVE-2026-56155 is an elevation of privilege flaw in Active Directory Federation Services. It requires local access and low privileges to start, which sounds like a limited threat until you remember that AD FS is identity infrastructur

    newssecurityaffairs.comJul 14, 2026, 9:33 PM
  • ication denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in July Patch Tuesday Edition CVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability Insufficient granularity of access control in Active Directory Federation Services (AD FS) could allow an authenticated attacker to elevate priv

    vendorblog.qualys.comJul 14, 2026, 9:23 PM
  • ed as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileg

    vendorblog.talosintelligence.comJul 14, 2026, 8:27 PM
  • edits incident responders for both. Both are elevation-of-privilege flaws in identity and collaboration infrastructure: CVE-2026-56164 in on-premises SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. Neither is one of the splashy remote code execution criticals. They are privilege bugs in two systems that matter more than th

    newsthehackernews.comJul 14, 2026, 8:25 PM
  • luding two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as C

    newswww.securityweek.comJul 14, 2026, 6:50 PM
  • ile no official fix is available. The two actively exploited zero-days addressed during this month's Patch Tuesday are: CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in Active Directory Federation Services that grants administrative privileges. "Insuf

    newswww.bleepingcomputer.comJul 14, 2026, 6:01 PM
  • The July 2026 Security Update ReviewZero Day Initiative

    oser look at some of the more interesting updates for this month, starting with the bugs being exploited in the wild. - CVE-2026-56155 - Active Directory Federation Services Elevation of Privilege Vulnerability This is one of several AD FS being patched this month, but it’s the only one being actively exploited. It stems from insufficient access-contro

    vendorwww.thezdi.comJul 14, 2026, 5:56 PM
  • No excerpt available.

    Mitigationwww.cisa.govJul 14, 2026, 5:17 PM
  • Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    vendormsrc.microsoft.comJul 14, 2026, 2:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence