• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-50522: pre-auth remote code execution in Microsoft SharePoint

An unauthenticated attacker can execute arbitrary code over the network against Microsoft SharePoint by exploiting a deserialization flaw (CVE-2026-50522). The vulnerability affects SharePoint Server 2016, Server 2019, and Server Subscription Edition in the 16.x branch prior to the fixed builds listed by Microsoft. No user interaction or valid account is required; an attacker only needs network access to a vulnerable SharePoint instance.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.03042
CWE
CWE-502
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog with a near-term remediation deadline, and public exploit code exists, so prioritize patching or applying vendor mitigations for internet-facing SharePoint deployments.

What is CVE-2026-50522?

An unauthenticated attacker can execute arbitrary code over the network against Microsoft SharePoint by exploiting a deserialization flaw (CVE-2026-50522). The vulnerability affects SharePoint Server 2016, Server 2019, and Server Subscription Edition in the 16.x branch prior to the fixed builds listed by Microsoft. No user interaction or valid account is required; an attacker only needs network access to a vulnerable SharePoint instance. The weakness is classified as CWE-502 (Deserialization of Untrusted Data).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft SharePoint are affected?

BRANCHAFFECTEDFIXED
Microsoft SharePoint Enterprise Server 2016 16.x16.0.0 – before 16.0.5561.100116.0.5561.1001
Microsoft SharePoint Server 2019 16.x16.0.0 – before 16.0.10417.2017516.0.10417.20175
Microsoft SharePoint Server Subscription Edition 16.x16.0.0 – before 16.0.19725.2043416.0.19725.20434

Is CVE-2026-50522 being exploited?

CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog on 2026-07-22, and US federal agencies were required to mitigate it by 2026-07-25. Public exploit code is available.

How to fix CVE-2026-50522

  1. Apply Microsoft’s security updates: install 16.0.5561.1001 for SharePoint Server 2016, 16.0.10417.20175 for Server 2019, or 16.0.19725.20434 for Subscription Edition.
  2. If you cannot patch immediately, follow Microsoft’s mitigation guidance and restrict network exposure of SharePoint to trusted hosts only.
  3. Monitor SharePoint logs and network traffic for signs of exploitation and audit recent administrator and process activity.
  4. Follow CISA and vendor guidance for prioritization and forensic triage as required by applicable policies.

Frequently asked questions

Is CVE-2026-50522 being actively exploited?

CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog on 2026-07-22 and required remediation by 2026-07-25; public exploit code is also available.

Which SharePoint versions are affected by CVE-2026-50522?

SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition in the 16.x branch are affected prior to the fixed builds specified by Microsoft.

Is there a patch for CVE-2026-50522?

Yes — Microsoft published fixes: 16.0.5561.1001 for Server 2016, 16.0.10417.20175 for Server 2019, and 16.0.19725.20434 for Subscription Edition.

Does CVE-2026-50522 require authentication?

No — the vulnerability allows unauthenticated network access to trigger deserialization and achieve remote code execution against vulnerable SharePoint instances.

References