CVE-2026-50522

Published Jul 14, 2026

Last updated a month ago

Exploit knownCVSS critical 9.8
Microsoft Office
ICS
Server
SharePoint

Overview

AI description

Verified by Intruder
Automated description summarized from trusted sources.

CVE-2026-50522 is identified as a deserialization vulnerability affecting Microsoft Office SharePoint. This flaw enables an unauthorized attacker to execute code remotely over a network. The vulnerability was addressed as part of Microsoft's July 2026 Patch Tuesday updates.

Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Insights

Analysis from the Intruder Security Team
Published Jul 21, 2026

This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsofts 'Patch Tuesday' security rollup.

A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Exploit added on
Jul 22, 2026
Exploit action due
Jul 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score
Not currently trending
  1. Swiss Gov hit via SharePoint vulnerabilities (CVE-2026-56164 & CVE-2026-50522) 200 user & technical accounts compromised. If technical accounts fall, privilege boundary fails. Patch now! #CyberSecurity #Vulnerability #CyberAttack #ThreatIntel #SharePoint #NetShieldTec

    @NetShieldTechAI

    10 Aug 2026

    8 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-of-the-Day: CVE-2026-50522 — SharePoint hands out remote code execution to anyone who asks. MS SharePoint deserializes untrusted data from a network request. An unauthenticated attacker can turn that into code execution on the server — no credentials, no user intera

    @YourDailyCVE

    31 Jul 2026

    12 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  3. This week’s What to Watch, Patch, and Secure roundup covers emerging threats, patching priorities, and enterprise exposure risks. 🔹 SharePoint RCE CVE-2026-50522 Attackers are exploiting an on-premises SharePoint RCE flaw that can expose IIS machine keys, making investigat

    @thehexnode

    31 Jul 2026

    94 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CVE-2026-50522: critical unauthenticated RCE in on-prem SharePoint Server (2016/2019/SE). Get the Nuclei detection template and scan at scale with Sn1per. https://t.co/iX35uDWlGF #infosec #netsec #bugbounty #redteam #offsec #infosecurity #CVE #exploit #CVE-2026-50522 https://t.c

    @xer0dayz

    29 Jul 2026

    1039 Impressions

    1 Retweet

    25 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2026-50522: critical unauthenticated RCE in on-prem SharePoint Server (2016/2019/SE). Get the Nuclei detection template and scan at scale with Sn1per. https://t.co/JwqujgcCVW #infosec #netsec #bugbounty #redteam #offsec #infosecurity #CVE #exploit #CVE-2026-50522 https://t.c

    @Sn1perSecurity

    29 Jul 2026

    210 Impressions

    0 Retweets

    1 Like

    3 Bookmarks

    0 Replies

    0 Quotes

  6. CISA added CVE-2026-16232 and CVE-2026-50522 to its KEV Catalog on July 22, 2026, based on evidence of active exploitation by malicious cyber actors. https://t.co/eJyDNzhqQx

    @f1tym1

    26 Jul 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 🚨 CRITICAL: CVE-2026-50522 - Microsoft SharePoint deserialization flaw (CVSS TBD). Actively exploited per CISA KEV. Allows remote code execution over network. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/KWG4gfEfUY

    @DFIR_Lab

    26 Jul 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC. Towr reports active exploitation of SharePoint CVE-2026-50522 after a public PoC, with attackers stealing machine keys for persistence. https://t.co/ZwtjMclWgr

    @TonyaR36937

    25 Jul 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Still seeing substantial amounts of Microsoft SharePoint unpatched instances that have been added to @CISACyber Known Exploited Vulnerability catalog last few weeks. This includes CVE-2026-50522, CVE-2026-56164, CVE-2026-58644 with 878 IPs (1585 FQDNs) unpatched on 2026-07-23 ht

    @Shadowserver

    24 Jul 2026

    1704 Impressions

    6 Retweets

    15 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  10. Legacy exposure keeps paying off for attackers. SharePoint CVE-2026-50522 makes patching only the first s… CISA added CVE-2026-50522 to KEV after reports of active SharePoint exploitation, making ke… 🔗 Read → https://t.co/yNQyY6RAhV

    @fynn_JourX

    23 Jul 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🛑 SharePoint CVE-2026-50522 makes patching only the first step CISA added CVE-2026-50522 to KEV after reports of active SharePoint exploitation, making ke… 🔗 Details → https://t.co/uyZLNiaDDh

    @lucasverdan

    23 Jul 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🛡️We added Check Point SmartConsole vulnerability CVE-2026-16232 & Microsoft SharePoint vulnerability CVE-2026-50522 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/zNyW

    @CISACyber

    22 Jul 2026

    13121 Impressions

    9 Retweets

    23 Likes

    4 Bookmarks

    4 Replies

    2 Quotes

  13. 🔒 #CyberSecurity CVE-2026-50522: Microsoft SharePoint RCE Exploited to Steal Machine Keys "A critical security vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522, is being…" 🔗 https://t.co/rGtdndI98g #CyberSecurity #ThreatIntel #critical #zeroday #cve

    @SecurityAr58409

    22 Jul 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. 🔒 #CyberSecurity CVE-2026-50522: SharePoint Server RCE Exploitation — Detection and Remediation … "A critical security flaw in Microsoft SharePoint Server, tracked as CVE-2026-50522, has…" 🔗 https://t.co/733usW2wh6 #CyberSecurity #ThreatIntel #critical #zeroday #c

    @SecurityAr58409

    21 Jul 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🧠 Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC Critical CVE / Exploit: A third SharePoint Server flaw patched by Mi... https://t.co/uFlvI9A0vf #CVE #CyberSecurity #Cybersecurity #InfoSec

    @MyDooM15

    21 Jul 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🚨 Two critical vulnerabilities in on-premises Microsoft Office SharePoint Server allow RCE without authentication: CVE-2026-58644 and CVE-2026-50522. ▪️ Affected versions: on-premises editions of Microsoft SharePoint Server: SharePoint Server 2016, SharePoint Server 2019,

    @censysio

    17 Jul 2026

    2708 Impressions

    8 Retweets

    32 Likes

    16 Bookmarks

    1 Reply

    1 Quote

  17. 🔴 ALERTĂ: Vulnerabilități critice în Microsoft SharePoint. CVE-2026-50522 și CVE-2026-58644 (CVSS 9.8) permit execuție de cod la distanță. CVE-2026-58644 este exploatată activ. Detalii: https://t.co/9aM8F68MVH #DNSC #CyberSecurity #SharePoint https://t.co/QguYaw5A9d

    @DNSC_RO

    17 Jul 2026

    222 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations