Critical SharePoint RCE Vulnerability (CVE-2026-50522) Exposes Enterprises to Unauthenticated Attacks
A newly disclosed critical vulnerability, CVE-2026-50522, enables unauthenticated remote code execution (RCE) on on-premises Microsoft SharePoint servers, posing a severe risk to enterprise environments. With a CVSS score of 9.8, the flaw stems from improper deserialization of untrusted data a recurring issue in SharePoint throughout 2026.
The vulnerability affects SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition running on x64 deployments. Attackers can exploit it by sending a crafted serialized object to a vulnerable endpoint without authentication or user interaction, leading to arbitrary code execution in the server’s context. Successful exploitation could result in full server takeover, web shell deployment, theft of application secrets, and lateral movement across networks.
While Microsoft has not confirmed active exploitation of CVE-2026-50522, its EPSS score of 19.7% indicates a high near-term risk. Researchers at Defused observed undocumented .NET deserialization payloads targeting SharePoint sign-in endpoints in honeypot traffic, suggesting possible exploitation attempts. This activity aligns with CVE-2026-50522 rather than the related CVE-2026-58644, which requires Site Owner permissions and has been confirmed as actively exploited in the wild.
Both vulnerabilities were patched in Microsoft’s July 2026 security update, but over 10,000 internet-facing SharePoint servers remain exposed globally, according to Check Point and Censys. Affected versions include:
- SharePoint Enterprise Server 2016 (prior to 16.0.5561.1001)
- SharePoint Server 2019 (prior to 16.0.10417.20175)
- SharePoint Server Subscription Edition (prior to 16.0.19725.20434)
Microsoft’s patch must be applied across all SharePoint farm members to prevent exploitation gaps. Organizations are advised to monitor for anomalous unauthenticated requests to authentication endpoints and restrict internet exposure of on-premises SharePoint servers where possible. CVE-2026-58644 has already been added to CISA’s Known Exploited Vulnerabilities catalog, reinforcing the urgency of remediation.
Source: https://cybersecuritynews.com/sharepoint-rce-exploited-in-the-wild/
Microsoft_SharePoint cybersecurity rating report: https://www.rankiteo.com/company/microsoft_sharepoint
"id": "MIC1784643940",
"linkid": "microsoft_sharepoint",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Over 10,000 internet-facing '
'servers',
'industry': 'Technology/Enterprise',
'location': 'Global',
'name': 'Microsoft SharePoint Enterprise Server 2016',
'type': 'Software'},
{'customers_affected': 'Over 10,000 internet-facing '
'servers',
'industry': 'Technology/Enterprise',
'location': 'Global',
'name': 'Microsoft SharePoint Server 2019',
'type': 'Software'},
{'customers_affected': 'Over 10,000 internet-facing '
'servers',
'industry': 'Technology/Enterprise',
'location': 'Global',
'name': 'Microsoft SharePoint Server Subscription '
'Edition',
'type': 'Software'}],
'attack_vector': 'Network',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Application secrets, sensitive '
'data'},
'date_publicly_disclosed': '2026-07',
'description': 'A newly disclosed critical vulnerability, CVE-2026-50522, '
'enables unauthenticated remote code execution (RCE) on '
'on-premises Microsoft SharePoint servers, posing a severe '
'risk to enterprise environments. The flaw stems from improper '
'deserialization of untrusted data and affects SharePoint '
'Enterprise Server 2016, SharePoint Server 2019, and '
'SharePoint Server Subscription Edition. Attackers can exploit '
'it without authentication or user interaction, leading to '
'arbitrary code execution, full server takeover, web shell '
'deployment, theft of application secrets, and lateral '
'movement across networks.',
'impact': {'data_compromised': 'Application secrets, sensitive data',
'operational_impact': 'Full server takeover, lateral movement '
'across networks',
'systems_affected': 'Microsoft SharePoint servers'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'corrective_actions': 'Patch management, enhanced '
'monitoring, network '
'exposure restrictions',
'root_causes': 'Improper deserialization of '
'untrusted data'},
'recommendations': "Apply Microsoft's July 2026 security update, monitor for "
'anomalous unauthenticated requests, restrict internet '
'exposure of on-premises SharePoint servers, and ensure '
'patches are applied across all SharePoint farm members.',
'references': [{'source': 'Microsoft Security Update'},
{'source': 'Defused Research'},
{'source': 'Check Point and Censys'},
{'source': 'CISA Known Exploited Vulnerabilities Catalog'}],
'response': {'containment_measures': "Apply Microsoft's July 2026 security "
'update across all SharePoint farm '
'members, monitor for anomalous '
'unauthenticated requests, restrict '
'internet exposure of on-premises '
'SharePoint servers',
'enhanced_monitoring': 'Monitor for anomalous unauthenticated '
'requests to authentication endpoints',
'remediation_measures': 'Patch affected SharePoint versions '
'(16.0.5561.1001 for 2016, '
'16.0.10417.20175 for 2019, '
'16.0.19725.20434 for Subscription '
'Edition)'},
'title': 'Critical SharePoint RCE Vulnerability (CVE-2026-50522) Exposes '
'Enterprises to Unauthenticated Attacks',
'type': 'Remote Code Execution (RCE)',
'vulnerability_exploited': 'CVE-2026-50522'}