CVE-2026-50522

CRITICAL

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS v3.1 Score

9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Complexity
LOW
Privileges
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Published: 7/14/2026Modified: 7/15/2026

Related Intelligence (6)

MEDIUMVulnerability

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access. The post Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks appeared first on SecurityWeek .

CVE-2026-50522
SecurityWeek
HIGHVulnerability

CISA KEV: Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CVE-2026-50522Microsoft SharePoint
CISA KEV
CRITICALVulnerability

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]

CVE-2026-50522
BleepingComputer
CRITICALVulnerability

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network. Microsoft credited DEVCORE

CVE-2026-50522
The Hacker News
CRITICALZero Day

Patch Tuesday - July 2026

Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last

CVE-2026-55040CVE-2026-56164
Rapid7
CRITICALVulnerability

NVD CRITICAL: CVE-2026-50522 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut...

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVE-2026-50522
NIST NVD

References (1)