Skip to content
Data Breach

Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a b...

· Jul 21, 2026 · 3 min read · 👁 4 views
Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers.

The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a bug class that has repeatedly plagued SharePoint in 2026.

CVE-2026-50522 affects on-premises x64 deployments of Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

An attacker can send a specially crafted serialized object to a vulnerable endpoint without prior authentication or user interaction, triggering arbitrary code execution in the SharePoint server’s context.

SharePoint RCE Actively Exploited in the Wild

Successful exploitation can lead to full server takeover, deployment of web shells, theft of application secrets, and use of the compromised host as a foothold for lateral movement across the network.

Notably, the same July 2026 patch cycle addressed a companion flaw, CVE-2026-58644, which requires an attacker to already hold at least Site Owner permissions to inject and execute code, distinguishing it from the fully unauthenticated CVE-2026-50522.

Microsoft has confirmed active in-the-wild exploitation of CVE-2026-58644, while CVE-2026-50522 itself is not currently confirmed as exploited, though its EPSS score of roughly 19.7% signals a meaningful near-term risk.

Defused researchers monitoring honeypot traffic during the current SharePoint attack wave have observed an undocumented .NET deserialization payload targeting SharePoint sign-in endpoints, with request fingerprints carrying no authentication material.

This pattern aligns more closely with the unauthenticated profile of CVE-2026-50522 than with the Site Owner-gated CVE-2026-58644, prompting analysts to reassess the activity as likely tied to CVE-2026-50522 rather than an unrelated zero-day.

Independent tracking from Check Point and Censys corroborates that both CVEs were published together and patched in the same July 2026 update, with over 10,000 internet-facing SharePoint servers still exposed globally.

Affected Versions and Fixes

ProductVulnerable Prior ToNotes
SharePoint Enterprise Server 201616.0.5561.1001KB applies to both Server 2016 and Enterprise Server 2016
SharePoint Server 201916.0.10417.20175Requires the July 2026 cumulative update
SharePoint Server Subscription Edition16.0.19725.20434Latest supported branch

Takeaway for Defenders

  • Apply Microsoft’s July 2026 security update immediately across all SharePoint farm members, since inconsistent patching leaves gaps for lateral exploitation.
  • Retire or upgrade unsupported SharePoint deployments that cannot receive the fix.
  • Monitor for anomalous requests to sign-in and authentication endpoints, particularly unauthenticated .NET deserialization payloads that don’t match published proof-of-concept traffic.
  • Restrict internet exposure of on-premises SharePoint servers where feasible, given Shadowserver’s tally of thousands of exposed instances.
  • Review CISA’s Known Exploited Vulnerabilities catalog, which already lists the paired CVE-2026-58644 as actively exploited under Binding Operational Directive requirements.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Recommended for you