SharePoint's third actively-exploited flaw this month: patching isn't enough

· Carl Heaton · Security

If your business runs SharePoint on its own servers rather than through Microsoft 365, you need to check this one properly, not just patch it. CVE-2026-50522 is the third on-premises SharePoint Server vulnerability to come under active exploitation in July alone, and researchers are warning that patching does not remove an attacker who already got in.

What changed

Microsoft's July Patch Tuesday update fixed CVE-2026-50522, a critical deserialisation flaw (CVSS 9.8) in on-premises SharePoint Server that lets an attacker who can reach the server over the network execute code remotely. Microsoft rates it "exploitation more likely", and security vendor watchTowr says it already is: within days of a public proof of concept, watchTowr detected active attacks against real deployments.

The detail that matters most: watchTowr reports attackers are using the flaw to steal SharePoint's machine keys in a single request, and that stolen keys let them keep access after the server is patched. "Patching is not enough," the firm said. "Defenders should rotate credentials on any assets that may have been exposed." A separate vendor, Defused Cyber, has observed the same flaw being used to deliver a further malicious payload to SharePoint's sign-in page.

This is the third SharePoint Server flaw to see active exploitation this month, following CVE-2026-56164 and CVE-2026-58644 (also CVSS 9.8, added to CISA's Known Exploited Vulnerabilities catalog with a mandated fix deadline for US federal agencies). CISA has separately warned that a further two SharePoint CVEs, CVE-2026-32201 and CVE-2026-45659, are also under attack. All affect SharePoint Server Subscription Edition, 2019, and 2016, on-premises deployments only. SharePoint Online, the version most Microsoft 365 subscribers actually use, is not affected by any of these.

What to check

  • Confirm which SharePoint you actually run. If your business uses Microsoft 365 and SharePoint Online, this specific run of vulnerabilities does not apply to you. If IT set up an on-premises SharePoint Server at some point and nobody has revisited that decision since, that is worth finding out today.
  • If you do run on-premises SharePoint Server, confirm the July Patch Tuesday updates are actually applied, not just scheduled.
  • Rotate SharePoint's machine keys regardless of whether you believe you were exploited before patching. The whole point of the attack is that stolen keys survive a patch.
  • Ask whoever manages the server directly: has anyone reviewed logs for the exposure window between the vulnerability's disclosure and your patch date?

The pattern worth noticing

Three critical, actively-exploited flaws in the same product in a single month is not routine bad luck. On-premises SharePoint has become a favoured target precisely because it sits on servers many businesses manage themselves, with patching cadence and monitoring that varies far more than Microsoft's own cloud service. If keeping an eye on a self-managed SharePoint Server is stretching your capacity, that is a legitimate moment to ask whether the reasons you set it up on-premises still hold.

How Steelwise can help

Confirming which SharePoint you run, checking whether the July patches actually landed, and reviewing for signs of prior access are the kind of practical checks we do with clients. Get in touch.

Further reading

← All filings