A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused.
The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network.
Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.
The initial disclosure was part of a larger July 14 patch release by Microsoft. The company said exploitation of the flaw would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack.
Researchers at watchTowr warned, however, that patching is not enough to address the deserialization flaw and that security teams “should rotate credentials on any assets that may have been exposed.”
According to watchTowr’s team, the vulnerability is extremely serious, telling Cybersecurity Dive the latest exploit has “ToolShell-class impact.” ToolShell was a summer 2025 campaign by ransomware and state-linked groups where hundreds of SharePoint customers were compromised. Multiple federal agencies were hit in the attacks.
CISA alert
Just one week ago, the Cybersecurity and Infrastructure Security Agency warned of three vulnerabilities in SharePoint facing exploitation:
- An improper input validation vulnerability, tracked as CVE-2026-32201, allows an attacker to perform spoofing over a network.
- A remote code execution vulnerability, tracked as CVE-2026-45659, involves deserialization of untrusted data.
- The third vulnerability, CVE-2026-56164, allows an attacker to elevate privileges over a network. According to ShadowServer Foundation, more than 1,000 instances are exposed, with about half of them located in North America.