Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Microsoft SharePoint Vulnerability Actively Exploited

A critical security flaw in Microsoft SharePoint has been found and is actively being exploited by attackers. This flaw allows unauthorised users to run harmful code remotely, potentially compromising sensitive information or systems. Small organisations using SharePoint should act quickly to reduce risk.

23 July 2026

Reference: CVE-2026-50522

1. What is being reported?

Researchers and security agencies have identified a serious weakness in Microsoft SharePoint software. The problem involves how SharePoint processes certain data, allowing attackers to run malicious commands over the internet without permission.

2. What this means in plain English

If your organisation uses SharePoint, attackers could exploit this flaw to take control of your system remotely. This could lead to data theft, disruption of services, or further attacks on your network. It is a high-risk issue that needs prompt attention.

3. Could this affect a small business?

Small businesses or charities using Microsoft SharePoint, especially if it is accessible from the internet, are at risk. Those not using SharePoint or only using cloud services with managed security may be less affected but should still check with their IT provider.

4. What to do now

  • Contact your IT provider or software supplier immediately to confirm if your SharePoint installation is affected.
  • Apply any security updates or patches provided by Microsoft as soon as they are available.
  • Review your SharePoint internet exposure and restrict access where possible.
  • Follow any additional mitigation steps recommended by your IT provider or Microsoft.

5. Ask your IT provider

Can you confirm if our Microsoft SharePoint system is affected by CVE-2026-50522 and what steps are being taken to protect us?

6. Bottom line

If you use Microsoft SharePoint, act quickly to check and apply security updates to prevent attackers from exploiting this critical flaw.

Information based on CISA KEV, NVD, and multiple reputable security news reports.

Back to Vulnerability Briefs