A critical, unauthenticated remote code execution flaw in Microsoft SharePoint Server is now under active exploitation, creating a race for administrators to secure their on-premises systems.

The vulnerability, designated CVE-2026-50522, was patched by Microsoft in its July 2026 security update. However, the window for defense closed rapidly. According to research from security firm watchTowr, as reported by The Hacker News, the flaw has moved from patch release to public proof-of-concept and finally to real-world attacks in an exceptionally compressed timeline.

The core issue is a deserialization vulnerability that allows a remote attacker, without authentication, to execute arbitrary code on the target server. By sending a crafted request, a threat actor can gain full control of a vulnerable SharePoint instance.

This grants attackers complete access, enabling data theft, ransomware deployment, and lateral movement within a corporate network. The straightforward nature of the exploit makes it a prime target for malicious campaigns.

The incident highlights the critical and shrinking window between patch deployment and real-world exploitation, placing immense pressure on IT teams. The operational challenge of rapidly applying updates across complex, distributed environments remains a significant hurdle that adversaries are keen to exploit.

On-premises administrators must treat this as a top-priority incident. The primary and most effective action is to immediately apply the July 2026 security updates. If patching is not immediately feasible, interim mitigation steps as outlined in Microsoft's advisory should be implemented, alongside heightened monitoring for anomalous SharePoint activity.


Microsoft SharePoint Server 中一個嚴重的無需驗證遠端代碼執行漏洞正遭到積極利用,令管理員必須與時間競賽以確保其本地部署系統的安全。

該漏洞被指定為 CVE-2026-50522,微軟已於 2026 年 7 月的安全更新中為其修補。然而,防禦窗口迅速關閉。根據保安公司 watchTowr 的研究(由 The Hacker News 報導),該漏洞從補丁發佈到公開的概念驗證(proof-of-concept),最終到達實際攻擊,經歷了異常緊縮的時間表。

核心問題是一個反序列化漏洞,允許遠端攻擊者無需驗證即可在目標伺服器上執行任意代碼。透過發送精心設計的請求,威脅行為者可以完全控制一個易受攻擊的 SharePoint 實例。

這賦予攻擊者完整存取權限,使其能進行資料竊取、部署勒索軟件,並在企業網絡內進行橫向移動。該漏洞利用方式的直接性使其成為惡意活動的首要目標。

此事件突顯了補丁部署與實際利用之間關鍵且日益縮短的窗口,對 IT 團隊造成巨大壓力。在複雜分散環境中快速應用更新的操作挑戰,仍是對手急於利用的重大障礙。

本地部署管理員必須將此視為首要事件。首要且最有效的行動是立即應用 2026 年 7 月的安全更新。若無法立即修補,則應實施微軟安全公告中概述的臨時緩解措施,同時加強對異常 SharePoint 活動的監控。

新聞來源 / Original News Source