NEW: Group Profiler — instant APT intel lookup. Try it →

← all advisories

CVE-2026-50522

Confirmed by 3 independent sources tracked by ThreatFilter. First reported 2026-07-14 14:00 UTC , most recent 2026-07-22 00:00 UTC.

MEDIUM 9.8 CISA KEV EXPLOITED microsoft

Corroboration timeline

Each row is the first time that source reported this CVE, so the lag column shows how long each took relative to the earliest report. Independent corroboration is a confidence signal that a single advisory cannot give you.

  1. microsoft-msrc 2026-07-14 14:00 UTC

    CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability

  2. thehackernews 2026-07-21 14:57 UTC +7d

    Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

  3. cisa-kev 2026-07-22 00:00 UTC +7d

    CVE-2026-50522 — Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

How this page is built

ThreatFilter ingests 52 public threat-intelligence feeds. A page is published here only when at least 3 distinct sources report the same CVE — roughly 0.2% of the CVEs seen. Everything above is derived from those feeds; nothing is hand-written, and the timeline is the raw record of what each source published and when.

See the live advisory feed, the full source list, or the analyst tools.