Junglewise Threat Intelligence

CVE-2026-50522: Microsoft SharePoint remote code execution via unsafe deserialization

CVE-2026-50522 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-07-14

Executive brief

Microsoft SharePoint, a widely used collaboration and document management platform, contains a critical security flaw that allows remote attackers to take control of the server. An unauthorized user can exploit this vulnerability over the network to execute malicious commands, potentially leading to full data theft or service disruption. This vulnerability has been reported as exploited in the wild, making immediate patching essential to protect corporate data and operations.

Technical details

A critical deserialization vulnerability (CWE-502) exists in Microsoft SharePoint Server. The flaw stems from the improper handling of untrusted data during deserialization, which allows an unauthenticated attacker to achieve remote code execution (RCE). The attack can be carried out over the network without any user interaction or prior privileges. Affected versions include SharePoint Server 2016, 2019, and Subscription Edition. Microsoft has released security updates to address this issue, and CISA has confirmed active exploitation in the wild.

Affected products

  • Microsoft SharePoint Server 2019 Prior to 16.0.10417.20175
  • Microsoft SharePoint Enterprise Server 2016 Prior to 16.0.5561.1001
  • Microsoft SharePoint Server Subscription Edition Prior to 16.0.19725.20434

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft Corporation
  • 2026-07-15: patched: Patch information added to NVD record
  • 2026-07-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats