Microsoft SharePoint and Windows Vulnerabilities Prompt Urgent Patches
Security researchers reported active exploitation of a critical Microsoft SharePoint flaw identified as CVE‑2026‑50522. After a proof‑of‑concept exploit was released on 20 July, the watchTowr honeypot network observed attackers stealing machine‑key credentials from vulnerable SharePoint servers, enabling creation of valid authentication tokens even after patches were applied. Microsoft addressed the deserialization bug in its July 2026 security update, and experts advised organizations to apply the patch and rotate all affected credentials.
Separately, the zero‑day vulnerability known as LegacyHive, disclosed by researcher Nightmare Eclipse, targets the Windows user‑profile service. A standard account can exploit the flaw to access another user's profile, exfiltrate sensitive data, or gain elevated privileges. In the absence of an official Microsoft fix, ACROS Security released a free micropatch through its 0patch platform, covering Windows 10 (version 2004+), Windows 11 and Windows Server 2022+. Installation requires a 0patch account and agent on the affected machines.