Back to news

Microsoft's Record 570-Flaw Patch Tuesday Includes Actively Exploited SharePoint RCE

A critical SharePoint deserialization vulnerability is being exploited in the wild just as Microsoft discloses its largest-ever monthly patch batch, driven in part by AI-assisted vulnerability discovery.

Microsoft's Record 570-Flaw Patch Tuesday Includes Actively Exploited SharePoint RCE

What happened

Microsoft's July 2026 Patch Tuesday addressed 570 security vulnerabilities across Windows and related software — nearly triple the previous month's record-breaking count — with the company attributing the surge partly to AI-assisted vulnerability research. Among the fixes was a patch for CVE-2026-50522, a critical deserialization flaw in SharePoint Server carrying a CVSS score of 9.8. Security firm watchTowr has confirmed the vulnerability is now under active exploitation following the public release of a proof-of-concept exploit. The flaw allows an unauthenticated remote attacker to execute arbitrary code over a network, and was originally discovered and reported by DEVCORE.

Why it matters for your business

A CVSS 9.8 rating on an unauthenticated remote code execution flaw means an attacker requires no credentials and no user interaction to compromise an exposed SharePoint instance — making this one of the highest-severity threat profiles possible. Organizations running on-premises SharePoint deployments are at immediate risk, particularly now that a working public exploit is circulating. The practical takeaway is unambiguous: apply the July 2026 SharePoint patch immediately, verify no internet-facing SharePoint servers remain unpatched, and review access logs for anomalous activity from before the patch was applied. The broader 570-flaw patch load also means security teams face an unusually heavy triage burden this cycle and should prioritize by exploitability and exposure.

What to watch next

With AI-assisted tooling accelerating the rate at which vulnerabilities are discovered — and disclosed — patch volumes of this scale may become the new normal rather than an outlier. Security teams should monitor for additional CVEs from the July batch moving to active-exploitation status, as threat actors routinely weaponize newly public patches. The trend also raises longer-term questions about whether enterprise patch management workflows, staffing, and tooling are scaled to handle sustained high-volume disclosure cycles.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp