Known Exploited Vulnerability
9.8
CRITICAL CVSS 3.1
CVE-2026-50522
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability - [Actively Exploited]
Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

INFO

Published Date :

July 14, 2026, 5:17 p.m.

Last Modified :

July 23, 2026, 3:44 p.m.

Remotely Exploit :

No
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Required Action :

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Known Ransomware Campaign Use:

Unknown

Notes :

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-50522

Affected Products

The following products are affected by CVE-2026-50522 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Microsoft sharepoint_server
2 Microsoft sharepoint_enterprise_server_2016
3 Microsoft sharepoint_server_2016
4 Microsoft sharepoint_server_2019
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 CRITICAL f38d906d-7342-40ea-92c1-6c4a2c6478c8
CVSS 3.1 CRITICAL [email protected]
Public PoC/Exploit Available at Github

CVE-2026-50522 has a 5 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-50522.

URL Resource
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 Patch Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522 US Government Resource
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-50522 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-50522 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

CVE-2026-50522 - Draft

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : July 22, 2026, 1:04 a.m. This repo has been linked 2 different CVEs too.

None

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 10, 2026, 2:42 p.m. This repo has been linked 1 different CVEs too.

Hello World

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : Nov. 29, 2025, 11 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week, 6 days ago
2 stars 0 fork 0 watcher
Born at : Jan. 20, 2023, 1:11 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 week, 6 days ago
0 stars 0 fork 0 watcher
Born at : Jan. 14, 2023, 11:38 a.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-50522 vulnerability anywhere in the article.

  • The Hacker News
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following ... Read more

Published Date: Aug 04, 2026 (3 hours, 34 minutes ago)
  • The Hacker News
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report ... Read more

Published Date: Aug 03, 2026 (18 hours, 19 minutes ago)
  • The Hacker News
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. C ... Read more

Published Date: Aug 03, 2026 (1 day, 3 hours ago)
  • The Hacker News
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, op ... Read more

Published Date: Aug 03, 2026 (1 day, 3 hours ago)
  • The Hacker News
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code exe ... Read more

Published Date: Aug 01, 2026 (3 days, 3 hours ago)
  • The Hacker News
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined ... Read more

Published Date: Jul 31, 2026 (3 days, 21 hours ago)
  • The Hacker News
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and ev ... Read more

Published Date: Jul 31, 2026 (3 days, 22 hours ago)
  • The Hacker News
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the ... Read more

Published Date: Jul 31, 2026 (3 days, 23 hours ago)
  • The Hacker News
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen.This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind ... Read more

Published Date: Jul 30, 2026 (4 days, 19 hours ago)
  • The Hacker News
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed finan ... Read more

Published Date: Jul 30, 2026 (5 days ago)
  • The Hacker News
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (O ... Read more

Published Date: Jul 30, 2026 (5 days, 2 hours ago)
  • The Hacker News
FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the ... Read more

Published Date: Jul 30, 2026 (5 days, 3 hours ago)
  • The Hacker News
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploi ... Read more

Published Date: Jul 30, 2026 (5 days, 5 hours ago)
  • The Hacker News
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated rem ... Read more

Published Date: Jul 29, 2026 (5 days, 18 hours ago)
  • The Hacker News
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbit ... Read more

Published Date: Jul 29, 2026 (5 days, 22 hours ago)
  • The Hacker News
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management ... Read more

Published Date: Jul 29, 2026 (6 days, 1 hour ago)
  • The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login

Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) pro ... Read more

Published Date: Jul 28, 2026 (6 days, 19 hours ago)
  • The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software rep ... Read more

Published Date: Jul 28, 2026 (6 days, 21 hours ago)
  • The Hacker News
Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-aft ... Read more

Published Date: Jul 28, 2026 (1 week ago)
  • The Hacker News
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVS ... Read more

Published Date: Jul 28, 2026 (1 week ago)

The following table lists the changes that have been made to the CVE-2026-50522 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Modified Analysis by [email protected]

    Jul. 23, 2026

    Action Type Old Value New Value
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522 Types: US Government Resource
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 23, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-22T20:45:10.104482Z'} {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-13T00:00:00+00:00'}
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Jul. 22, 2026

    Action Type Old Value New Value
    Added Date Added 2026-07-22
    Added Due Date 2026-07-22
    Added Required Action 2026-07-22
    Added Vulnerability Name 2026-07-22
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 22, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-13T00:00:00+00:00'} {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-22T20:45:10.104482Z'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 22, 2026

    Action Type Old Value New Value
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50522
  • Initial Analysis by [email protected]

    Jul. 15, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:* *cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* versions up to (excluding) 16.0.19725.20434
    Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 Types: Patch, Vendor Advisory
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 15, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-14T17:44:07.905626Z'} {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-13T00:00:00+00:00'}
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jul. 14, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-50522', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-07-14T17:44:07.905626Z'}
  • New CVE Received by [email protected]

    Jul. 14, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Enterprise Server 2016', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.5561.1001', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server 2019', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.10417.20175', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Microsoft SharePoint Server Subscription Edition', 'versions': [{'status': 'affected', 'version': '16.0.0', 'lessThan': '16.0.19725.20434', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}]
    Added Description Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-502
    Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.