All news

SharePoint CVE-2026-50522: critical RCE under active exploitation

Microsoft MSRCSummarized by the ORA·tech AI assistant
SEC

CVE-2026-50522 is a deserialization flaw in Microsoft SharePoint Server, CVSS 9.8, allowing unauthenticated remote code execution. CISA added it to KEV on July 22 with a July 25 patch deadline for US federal agencies.

Microsoft has shipped a fix for CVE-2026-50522, a deserialization-of-untrusted-data flaw in SharePoint Server that enables remote code execution (RCE). Rated critical at CVSS 9.8, an unauthenticated attacker can send a crafted serialized payload over the network to trigger unsafe deserialization and run code in the context of the SharePoint service account.

Key points

  • Affected: SharePoint Server Subscription Edition, SharePoint Server 2019 and 2016 Enterprise (on-premises).
  • Active exploitation: CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on July 22, 2026, with a July 25 patch deadline for US federal (FCEB) agencies - a signal it is being abused in the wild.
  • Remediation: patch immediately per Microsoft's Security Update Guide; for SharePoint deserialization bugs, consider rotating ASP.NET machine keys after patching and review logs for anomalous hits on authentication endpoints.

Affected builds and patch details are in the MSRC advisory - see Read original.

Source
Microsoft MSRC
Read the original
#CVE#SharePoint#Microsoft#RCE#CISA KEV
This summary was written by the ORA·tech AI assistant. Read the original for full context.

Related