A critical SharePoint Server vulnerability tracked as CVE-2026-50522 is reportedly being actively exploited after a public proof-of-concept became available. The issue was one of the flaws addressed by Microsoft during its July 2026 Patch Tuesday updates.

According to the report cited in the source material, security researchers at watchTowr observed real-world exploitation activity tied to the bug. The concern has grown because the vulnerability is described as a remote code execution flaw, making it especially serious for organizations running affected SharePoint environments.

The report also says attackers are stealing machine keys, a tactic that can help them maintain persistence after the initial compromise. That detail suggests the activity is not limited to one-off access attempts and may be aimed at keeping a foothold on impacted systems.

The development adds pressure on organizations to review Microsoft's July 2026 SharePoint patches and assess whether exposed servers may have been targeted already. With public exploit code now linked to active attacks, CVE-2026-50522 has quickly become a high-priority SharePoint security issue.