Skip to content
feed: live
>_ 0dayNews
CVE Record
[ CRITICAL ] CVE-2026-50522

SharePoint Server deserialization of untrusted data RCE

Critical deserialization flaw in Microsoft Office SharePoint Server, CVSS 9.8, allowing an unauthenticated attacker to execute code over a network. Patched July 2026.

cat cve-2026-50522.json
Vendor
Microsoft
Product
SharePoint Server
CVSS
9.8
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

Microsoft patched CVE-2026-50522 on July 14, 2026, as part of the July Patch Tuesday release. It is the third SharePoint Server remote-code-execution flaw addressed in that same cycle. Microsoft credits DEVCORE for the discovery.

The vulnerability class is deserialization of untrusted data, reachable over the network without authentication. NVD scores it 9.8 (Critical) under CVSS 3.1.

Active exploitation was reported by watchTowr on 2026-07-21, following the circulation of a public proof-of-concept. Coverage: SharePoint CVE-2026-50522 exploited after public PoC.

Remediation is Microsoft’s July 2026 SharePoint security updates. See the MSRC entry for CVE-2026-50522 and the NVD record.