CVE-2026-50522
A critical vulnerability in Microsoft SharePoint Server allows attackers to execute arbitrary code by sending specially crafted data. The flaw arises from unsafe deserialization of untrusted data. It can be exploited over a network without authentication.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Microsoft SharePoint Server (all versions, including 2016 and 2019) used by organizations that host SharePoint sites.
Real-world impact
An attacker could run arbitrary code on the SharePoint server, potentially taking control of the system, stealing data, or using it to move laterally within the network.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely with no authentication, giving the attacker full control over the system, and it has a high impact on confidentiality, integrity, and availability.
What to do about it
- 01Follow Microsoft’s vendor instructions to apply the recommended mitigations for CVE-2026-50522.
- 02Ensure compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk guidance.
- 03If mitigations are unavailable, discontinue use of the affected SharePoint product.
CISA KEV required action
Timeline
- Jul 14, 2026 · 20d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 22, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 10d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…patchvendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource