[KEV] CVE-2026-50522 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-50522 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-50522 is a deserialization of untrusted data vulnerability in Microsoft SharePoint that could allow an unauthorized remote attacker to execute code on an affected SharePoint server.
Technical Detail
The flaw arises when Microsoft SharePoint processes untrusted serialized data without sufficient validation. An attacker could send crafted data to a vulnerable SharePoint instance over the network and trigger unsafe deserialization. Successful exploitation could result in remote code execution (RCE) in the context of the affected SharePoint service.
Exploitation Status
Exploit maturity is assessed as Operational, indicating that functional exploitation capability is available for practical use. CISA has confirmed active exploitation in the wild. CVE-2026-50522 was added to the CISA Known Exploited Vulnerabilities Catalog on July 22, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize deployment of Microsoft security updates for affected SharePoint installations and verify that all internet-accessible and internally exposed SharePoint servers are remediated. Under CISA Binding Operational Directive 22-01 requirements, federal civilian executive branch agencies must patch by August 12, 2026, or apply mitigations. Where immediate patching is not possible, restrict network access to SharePoint services, limit access to trusted users and networks, and monitor SharePoint and Windows event logs for unusual process execution, unexpected child processes spawned by SharePoint-related services, abnormal web requests, and signs of unauthorized code execution. No vendor workaround or specific detection signature is confirmed in the available data.