Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-50522

SharePoint Server deserialization of untrusted data RCE

Critical deserialization flaw in Microsoft Office SharePoint Server, CVSS 9.8, allowing an unauthenticated attacker to execute code over a network. Patched July 2026.

cat cve-2026-50522.json
Vendor
Microsoft
Product
SharePoint Server
CVSS
9.8
EPSS (exploit probability)
84.6%
Status
kev
CISA patch-by (BOD 22-01)
Published

Microsoft patched CVE-2026-50522 on July 14, 2026, as part of the July Patch Tuesday release. It is the third SharePoint Server remote-code-execution flaw addressed in that same cycle. Microsoft credits DEVCORE for the discovery.

The vulnerability class is deserialization of untrusted data, reachable over the network without authentication. NVD scores it 9.8 (Critical) under CVSS 3.1.

Active exploitation was reported by watchTowr on 2026-07-21, following the circulation of a public proof-of-concept. CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog on July 22, 2026.

Attackers are using the initial RCE to steal ASP.NET machine keys from compromised servers — patching the vulnerability does not rotate those keys. Affected organizations should patch AND rotate machine keys. See SharePoint RCE on KEV; Attackers Pivot to Machine Keys for remediation steps.

For background on initial exploitation: SharePoint CVE-2026-50522 exploited after public PoC.

Remediation is Microsoft’s July 2026 SharePoint security updates. See the MSRC entry for CVE-2026-50522 and the NVD record.