INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Public Exploitation of SharePoint RCE Vulnerability CVE-2026-50522
| 2026-07-21 14:57 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The critical Microsoft SharePoint vulnerability, CVE-2026-50522, is being actively exploited following the release of a public proof-of-concept (PoC) code. This deserialization-based remote code execution bug can be triggered without authentication or user interaction and stems from the deserialization of untrusted data. The vulnerability has been demonstrated live at Pwn2Own Berlin, with working exploits handed to Microsoft. Active exploitation is also observed on-premises by cybersecurity firms Defused Cyber and watchTowr, targeting a .NET deserialization payload through a SharePoint sign-in endpoint. This critical vulnerability requires no authentication, consistent with its unauthenticated remote code execution profile, making it a high-severity threat.
Technical Mitigations AI-generated
* Apply Microsoft's July 2026 Patch Tuesday updates immediately: Organizations should apply the available security updates to patch critical SharePoint RCE vulnerability CVE-2026-50522 as soon as possible.
* Rotate machine keys and other potentially exposed credentials: Security experts warn that organizations should not only apply Microsoft’s updates but also rotate machine keys and other potentially exposed credentials to prevent long-term compromise.
* Use secure coding practices: Organizations should ensure that their development teams follow secure coding practices, such as validating user input and using deserialization protection mechanisms, to reduce the risk of exploitation.
* Implement a web application firewall (WAF): WAFs can help block malicious traffic and prevent attacks from exploiting vulnerabilities like CVE-2026-50522.
* Monitor for suspicious activity: Organizations should regularly monitor their SharePoint servers for suspicious activity, such as unauthorized access or machine key theft, to detect potential exploitation attempts.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
we•••••.config
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-56164CVE-2026-56164
CVE-2026-25089CVE-2026-25089
CVE-2026-39808CVE-2026-39808
CVE-2026-45659CVE-2026-45659
CVE-2026-58644CVE-2026-58644
CVE-2026-20963CVE-2026-20963
CVE-2026-32201CVE-2026-32201
CVE-2026-50522CVE-2026-50522
Target & Sectors
Global Scope
governmentgovernment
Incident Timeline
March 2026
Threat actors used a known exploited vulnerability in SharePoint to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in March 2026.
Click on any entity below to view its context and source!
attribution
Known Exploited
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another SharePoint issue, tracked as
CVE-2026-20963
, its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1588.006 - Vulnerabilities
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another SharePoint issue, tracked as
CVE-2026-20963
, its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
KEV
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another SharePoint issue, tracked as
CVE-2026-20963
, its
Known Exploited Vulnerabilities (KEV) catalog
.
vulnerability
CVE-2026-20963
In March 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another SharePoint issue, tracked as
CVE-2026-20963
, its
Known Exploited Vulnerabilities (KEV) catalog
.
April 2026
Threat actors used a previously disclosed vulnerability in Microsoft SharePoint Server to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Microsoft SharePoint Server flaw, tracked as
CVE-2026-32201
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
vulnerability
CVE-2026-32201
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Microsoft SharePoint Server flaw, tracked as
CVE-2026-32201
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
Known Exploited
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Microsoft SharePoint Server flaw, tracked as
CVE-2026-32201
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
tactic
T1588.006 - Vulnerabilities
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Microsoft SharePoint Server flaw, tracked as
CVE-2026-32201
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
attribution
KEV
In April 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
added
another Microsoft SharePoint Server flaw, tracked as
CVE-2026-32201
, to its
Known Exploited Vulnerabilities (KEV) catalog
.
July 14, 2026
Threat actors used a remote exploit to target Microsoft SharePoint Server Subscription Edition and Microsoft SharePoint Enterprise Server 2016 versions.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
Redmond noted that the vulnerability is remotely exploitable over the internet, warning that the attack complexity is low for two reasons -
An attacker does not require significant prior knowledge of the system
An attacker can achieve repeatable success with the payload against the vulnerable component
The vulnerability impacts the following versions -
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Patches for the flaw have been
released
as part of the Patch Tuesday updates released on July 14, 2026.
organisation
Microsoft SharePoint
Redmond noted that the vulnerability is remotely exploitable over the internet, warning that the attack complexity is low for two reasons -
An attacker does not require significant prior knowledge of the system
An attacker can achieve repeatable success with the payload against the vulnerable component
The vulnerability impacts the following versions -
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Patches for the flaw have been
released
as part of the Patch Tuesday updates released on July 14, 2026.
general_metric
2016 Patches
Redmond noted that the vulnerability is remotely exploitable over the internet, warning that the attack complexity is low for two reasons -
An attacker does not require significant prior knowledge of the system
An attacker can achieve repeatable success with the payload against the vulnerable component
The vulnerability impacts the following versions -
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2016
Patches for the flaw have been
released
as part of the Patch Tuesday updates released on July 14, 2026.
2026/07/14
Threat actors used T1584.004 - Server to target a SharePoint server via critical Remote Code Execution (RCE) vulnerability CVE-2026-50522 under active exploitation after public proof of concept.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
"In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server," Redmond said in an advisory released last week.
Jul 17, 2026
Threat actors exploited CVE-2026-50522 in a critical SharePoint vulnerability to gain unauthorized access.
July 19, 2026
Threat actors used a previously patched vulnerability (CVE-2026-50522) in Microsoft SharePoint Server to target Federal agencies.
Click on any entity below to view its context and source!
tactic
T1584.004 - Server
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
Known Exploited
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
tactic
T1588.006 - Vulnerabilities
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
KEV
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
Vulnerability / Enterprise Security
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
Microsoft SharePoint
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
Federal Civilian Executive Branch
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
attribution
FCEB
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
general_metric
17 Jul
Ravie Lakshmanan
Jul 17, 2026
Vulnerability / Enterprise Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday
added
a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (
KEV
) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026.
July 20th
WatchTowr identified proof-of-concept exploit code for CVE-2026-50522 on July 20th.
Jul 21, 2026
Threat actors exploited CVE-2026-50522 in a critical SharePoint vulnerability to gain unauthorized access.
2026/07/21
Threat actors used a public proof-of-concept (PoC) exploit code to target Microsoft SharePoint Server, exploiting the critical deserialization of untrusted data vulnerability CVE-2026-50522.
Click on any entity below to view its context and source!
organisation
SharePoint RCE
Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522.
infrastructure
9.8
A critical Microsoft SharePoint vulnerability, tracked as
CVE-2026-50522
(CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.
organisation
Microsoft SharePoint
A critical Microsoft SharePoint vulnerability, tracked as
CVE-2026-50522
(CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.
organisation
PoC
A critical Microsoft SharePoint vulnerability, tracked as
CVE-2026-50522
(CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.
organisation
CVE-2026-50522
CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data.
organisation
CVE-2026
CVE-2026-50522 and CVE-2026-58644 are a matched pair of SharePoint remote code execution bugs; both can be triggered without authentication or user interaction, and stemming from the deserialization of untrusted data.
organisation
Cybersecurity
Cybersecurity firm Defused Cyber also spotted threat actors exploiting
CVE-2026-50522
to deliver a .NET deserialization payload through a SharePoint sign-in endpoint.
organisation
CVE-2026-32201
CVE-2026-32201
(CVSS score of 6.5) is a spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS).
organisation
CVSS
CVE-2026-32201
(CVSS score of 6.5) is a spoofing vulnerability in Microsoft SharePoint Server, likely related to cross-site scripting (XSS).
organisation
Internet Information Services
"These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware," the federal cybersecurity watchdog noted.
organisation
Microsoft
"In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server," Microsoft
said
in an advisory released earlier this week.
organisation
SharePoint Central Administration
Block external access to SharePoint Central Administration, restrict farm and database communications to required systems, and review Microsoft's
SharePoint Server security-hardening guidance
for role-specific ports, services, and Web.config settings.
infrastructure
Microsoft Office
The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
Microsoft Office SharePoint
The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
organisation
SharePoint
Verify that Antimalware Scan Interface (
AMSI
) integration is enabled for each SharePoint web application.
organisation
Attacker Eye
Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.”
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Microsoft)
organisation
Fortinet FortiSandbox
On Thursday, the agency also added two critical security flaws impacting Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog, following
reports
of
active exploitation
.
organisation
KEV
On Thursday, the agency also added two critical security flaws impacting Fortinet FortiSandbox (CVE-2026-25089 and CVE-2026-39808) to the KEV catalog, following
reports
of
active exploitation
.
organisation
SharePoint Servers
Avoid exposing SharePoint Servers directly to the internet unless necessary.
July 2026
Threat actors are exploiting CVE-2026-50522 to deliver a .NET deserialization payload to a SharePoint sign-in endpoint.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-50522
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Web Security
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per
watchTowr
.
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
The tech giant also tagged CVE-2026-50522 with an exploitability assessment of "Exploitation More Likely.
organisation
Vulnerability / Web Security
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Web Security
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per
watchTowr
.
tactic
T1584.004 - Server
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Web Security
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per
watchTowr
.
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
organisation
Microsoft
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Web Security
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per
watchTowr
.
Patched in Microsoft’s
July 2026 Patch Tuesday
, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.
general_metric
21 Jul
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC.
Ravie Lakshmanan
Jul 21, 2026
Vulnerability / Web Security
A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per
watchTowr
.
general_metric
9.8 score
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
vulnerability
CVE-2026-56164
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
vulnerability
CVE-2026-58644
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
infrastructure
5.3
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
infrastructure
9.8
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
organisation
CVE-2026
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
general_metric
5.3 third vulnerability
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2026.
organisation
SharePoint
Patched in Microsoft’s
July 2026 Patch Tuesday
, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.
"Attackers are pulling SharePoint machine keys via a single request," the security vendor said.
organisation
Site Owner
Patched in Microsoft’s
July 2026 Patch Tuesday
, the deserialization flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code remotely on vulnerable SharePoint servers.
infrastructure
Microsoft Office
The vulnerability in question is
CVE-2026-50522
(CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.
organisation
Microsoft Office SharePoint
The vulnerability in question is
CVE-2026-50522
(CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.
organisation
Internet Information Services
"These vulnerabilities affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution (RCE) and post-exploitation activities, such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware," the agency said.
organisation
DEVCORE
Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the flaw.
organisation
Network
"The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet.
organisation
LinkedIn
"
In a post shared on LinkedIn, watchTowr said it has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit, allowing attackers to steal machine keys to maintain persistent access.
organisation
Microsoft SharePoint
"
In a post shared on LinkedIn, watchTowr said it has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit, allowing attackers to steal machine keys to maintain persistent access.
organisation
PoC
"
In a post shared on LinkedIn, watchTowr said it has detected active exploitation of the shortcoming against on-premises Microsoft SharePoint deployments following the release of a public proof-of-concept (PoC) exploit, allowing attackers to steal machine keys to maintain persistent access.
Tactical Metrics
Metrics
infrastructure
Microsoft Office
Affected Product
Click for context!
The vulnerability in question is
CVE-2026-50522
(CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.
The vulnerability is a deserialization of untrusted data in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network.
Metrics
infrastructure
5.3
Software Version
CVE-2026-50522 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fix…
Metrics
infrastructure
9.8
Software Version
…22 is the third vulnerability in SharePoint Server after
CVE-2026-56164 (CVSS score: 5.3) and CVE-2026-58644
(CVSS score: 9.8) to witness active exploitation efforts, with the latter two weaponized as zero-days prior to them being fixed in July 2…
A critical Microsoft SharePoint vulnerability, tracked as
CVE-2026-50522
(CVSS score of 9.8), is being actively exploited following the release of a public proof-of-concept (PoC) code, according to watchTowr researchers.
Intelligence Sources
Security Affairs
2026-07-21
The Hacker News
2026-07-21
The Hacker News
2026-07-17
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-22T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
23x
organisation
Identified Entity
Vulnerability / Web Security
entity
12x
timeline
Temporal Reference
Jul 21, 2026
date
11x
attribution
Attributing Entity
The U.S. Cybersecurity and Infrastructure Security Agency
authority
8x
vulnerability
Exploited CVE
CVE-2026-50522
cve
2x
tactic
MITRE ATT&CK Technique
T1584.004 - Server
technique
2x
general metric
Jul
21
jul
2x
infrastructure
Software Version
5.3
version
2x
tactic
Cyber Operation Type
Remote Code Execution
tactic
2x
vulnerability
CVSS Score
6
score
Contextual Telemetry
Context Block
6 METRICS
infrastructure
Affected Product
Microsoft Office
software
general metric
Score
10
score
general metric
Third Vulnerability
5
third vulnerability
general metric
Cve-2026
58,644
cve-2026
general metric
Fortinet Fortisandbox
39,808
fortinet fortisandbox
general metric
Patches
2,016
patches
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.