Signal

Critical SharePoint vulnerabilities exploited in recent wave of attacks

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-07-22 00:00 UTCUpdated 2026-07-22 11:29 UTC
rss
cveexploitssecurity_advisoriesincident_response
Trend in the last 24h
Current brief openSource links open
This current signal is open on the public brief with summary, metadata, source links, and full evidence. Pro adds compare-over-time, alerts, exports, and workflow.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
CERT-EU Security Advisories
cert.europa.eu · cert.europa.eu · 2026-07-22 08:48 UTC
Overview

In July 2026, Microsoft released patches for multiple critical vulnerabilities in SharePoint, including CVE-2026-50522 and CVE-2026-58644, which allow unauthenticated remote code execution.

Entities
MicrosoftSharePointEduard Kovacs
Score total
1.21
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Exploit code and attacks emerged rapidly after patch release in July 2026.
  • Multiple advisories highlight active exploitation, emphasizing urgency.
  • Organizations must act now to secure exposed SharePoint servers and credentials.
Why it matters
  • Critical SharePoint vulnerabilities enable remote code execution without authentication.
  • Exploitation allows attackers to steal keys and maintain long-term access, increasing breach impact.
  • Timely patching and credential rotation are essential to prevent widespread compromise.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • Microsoft SharePoint vulnerabilities CVE-2026-50522 and CVE-2026-58644 allow unauthenticated remote code execution.
  • Exploit code and active exploitation of SharePoint vulnerabilities have been observed shortly after patch release.
  • Attackers exploit CVE-2026-50522 to steal machine keys and maintain persistent access.
How sources frame it
  • CERT-EU: neutral
  • CERT-FR: neutral
  • SecurityWeek: neutral
All evidence
All evidence
CERT-EU Security Advisories
cert.europa.eu · cert.europa.eu · 2026-07-22 08:48 UTC
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
SecurityWeek · securityweek.com · 2026-07-22 11:29 UTC
Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)
CERT-FR (FR) - All · cert.ssi.gouv.fr · 2026-07-22 00:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • cert.europa.eu (1)
  • SecurityWeek (1)
  • CERT-FR (FR) - All (1)
Top origin domains (this list)
  • cert.europa.eu (1)
  • securityweek.com (1)
  • cert.ssi.gouv.fr (1)