- CVE: CVE-2026-50522
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Microsoft SharePoint Enterprise Server 2016
- Affected: 16.0.0
- Impact: Microsoft SharePoint Remote Code Execution Vulnerability
- Status: Exploited in the wild.
- Patched in: 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434
- EPSS: 20.3% (30-day)
- Action: Update to 16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434 now
TL;DR
CVE-2026-50522 is a critical SharePoint RCE flaw rated CVSS 9.8. Researchers report active exploitation attempts, and a public proof-of-concept exploit is now available. Microsoft patched the bug on July 14, 2026, so admins should update fast.
Why it matters
SharePoint runs document and intranet systems for many organizations. So a remote code execution bug here carries real risk. The flaw earns Microsoft’s top practical severity score. Microsoft describes a network attack by an “unauthorized attacker,” which points to an unauthenticated path. Internet-facing farms therefore face the highest exposure. Per Microsoft’s advisory, the flaw needs no user interaction.
How the attack works
This SharePoint RCE stems from unsafe deserialization of untrusted data (CWE-502). In short, the server rebuilds attacker-supplied objects it should reject. That trust then lets an attacker run code on the server. Deserialization flaws have struck SharePoint before, so the pattern looks familiar to defenders. This report shares no payloads or exploit steps.
Exploitation status
Researchers at Defused flagged an undocumented SharePoint deserialization vector hitting their honeypots. They later assessed the traffic as likely CVE-2026-50522, since the requests carried no authentication. Also, watchTowr confirm this. Microsoft says the paired CVE-2026-58644 needs Site Owner access, which does not match the unauthenticated traffic. Separately, researcher Janggggg published proof-of-concept exploit code. At disclosure, the CVE was not yet in CISA’s known-exploited catalog.
Affected versions
Microsoft lists on-premises SharePoint Server as affected. This covers Enterprise Server 2016, Server 2019, and the Subscription Edition. Notably, the 2016 fix applies to both Server and Enterprise Server builds.
Patch and mitigation
First, apply the July 2026 SharePoint security update now. If you cannot patch at once, limit external access to the farm. Also, hunt your logs for suspicious requests to SharePoint sign-in pages. Segmenting these servers reduces the blast radius of any breach. With a public PoC out, this SharePoint RCE will draw more attacks soon.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.