Microsoft SharePoint contains a critical deserialization flaw (CVSS 9.8) that lets an unauthenticated attacker run code over the network, and CISA confirms it is being actively exploited.
What Is It
CVE-2026-50522 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft Office SharePoint. Per Microsoft and NVD, the flaw allows an unauthorized attacker to execute code over a network. It carries a CVSS 3.1 base score of 9.8 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is remotely reachable, requires no privileges or user interaction, and fully compromises confidentiality, integrity, and availability.
Why It Matters
CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on 2026-07-22, confirming active exploitation in the wild. CISA's SSVC assessment rates exploitation as "active," automatable as "yes," and technical impact as "total." The combination of no authentication, low attack complexity, and full system impact makes this an attractive target for opportunistic and automated attacks. Known ransomware campaign use is currently listed as Unknown.
What's Vulnerable
The following on-premises SharePoint products (x64-based systems) are affected:
- SharePoint Enterprise Server 2016: versions below 16.0.5561.1001
- SharePoint Server 2019: versions below 16.0.10417.20175
- SharePoint Server Subscription Edition: versions below 16.0.19725.20434
Patch Status
Microsoft has published updated fixed builds (listed above) via its Security Response Center advisory. CISA's required action directs organizations to apply mitigations per vendor instructions in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue product use if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. The CISA remediation due date is 2026-07-25.