SharePoint CVE-2026-50522: critical RCE under active exploitation
CVE-2026-50522 is a deserialization flaw in Microsoft SharePoint Server, CVSS 9.8, allowing unauthenticated remote code execution. CISA added it to KEV on July 22 with a July 25 patch deadline for US federal agencies.
Microsoft has shipped a fix for CVE-2026-50522, a deserialization-of-untrusted-data flaw in SharePoint Server that enables remote code execution (RCE). Rated critical at CVSS 9.8, an unauthenticated attacker can send a crafted serialized payload over the network to trigger unsafe deserialization and run code in the context of the SharePoint service account.
Key points
- Affected: SharePoint Server Subscription Edition, SharePoint Server 2019 and 2016 Enterprise (on-premises).
- Active exploitation: CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on July 22, 2026, with a July 25 patch deadline for US federal (FCEB) agencies - a signal it is being abused in the wild.
- Remediation: patch immediately per Microsoft's Security Update Guide; for SharePoint deserialization bugs, consider rotating ASP.NET machine keys after patching and review logs for anomalous hits on authentication endpoints.
Affected builds and patch details are in the MSRC advisory - see Read original.
Source
Microsoft MSRC
#CVE#SharePoint#Microsoft#RCE#CISA KEV
This summary was written by the ORA·tech AI assistant. Read the original for full context.
Related
Security & DevSecOps
Microsoft launches Project Perception agentic security system
Security & DevSecOps
Check Point CVE-2026-16232: SmartConsole auth bypass exploited
Security & DevSecOps