Lyrie
Active Exploitation
1 sources verified·1 min read
By Lyrie Threat Intelligence·7/24/2026

0day Intel: YOU PATCHED THE SERVER. THE ATTACKER IS STILL INSIDE. CVE-2026-50522, AND WHY TH

Source: X search for CVE-2026 critical

Posted: 2026-07-23T18:07:51.000Z

Likes: 29

Full Tweet

YOU PATCHED THE SERVER. THE ATTACKER IS STILL INSIDE. CVE-2026-50522, AND WHY THE FIX CAME TOO LATE.

A critical SharePoint flaw, severity 9.8, under active exploitation this week. Unauthenticated remote code execution on every on-premise SharePoint: 2016, 2019, Subscription https://t.co/oKAFvkCI1v https://t.co/W4HmqQ3c6L

Source Link

https://x.com/i/status/2080354217470959700

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.

Validated sources

  1. [1]@1852642701340020736 on X