Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Alert: Active Exploitation of Microsoft SharePoint On-Premises Vulnerability

Microsoft has reported active exploitation of a newly disclosed vulnerability (CVE-2026-50522) affecting Microsoft SharePoint Server (On-Premises). According to Microsoft and security researchers, threat actors are exploiting the vulnerability to compromise vulnerable SharePoint servers, enabling unauthorized access and execution of malicious code.
 
Affected Systems:
  • Microsoft SharePoint Enterprise Server 2016 Versions prior to 16.0.5561.1001
  • Microsoft SharePoint Server 2019 Versions prior to 16.0.10417.20175
  • Microsoft SharePoint Server Subscription Edition Versions prior to 16.0.19725.20434
 
Security Risks
 
The identified vulnerabilities allow attackers to bypass security controls, remotely execute code, and steal cryptographic materials, compromising both the SharePoint environment and integrated Microsoft services.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to take the following actions to mitigate the active exploitation of these vulnerabilities:
  • Update immediately to the latest supported version of Microsoft SharePoint Server to address the vulnerabilities and mitigate associated risks.
  • Follow the guidance provided by Microsoft and implement the recommended mitigations to minimize the risk of exploitation.
  • Ensure you have a recent backup that can be restored easily before applying updates or workarounds.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.

References

23 July 2026

© 2026 National Cyber Security Authority