Critical on-prem SharePoint deserialization RCE CVE-2026-50522 (CVSS 9.8) patched; WatchTowr reports active exploitation and CISA urges hardening
Microsoft patched CVE-2026-50522 (CVSS 9.8, CWE-502), an unauthenticated .NET deserialization RCE in on-premises SharePoint Server Subscription Edition, 2019, and Enterprise 2016, in its 14 July 2026 security updates; on 20 July 2026 WatchTowr published PoC…
Microsoft fixed CVE-2026-50522, a critical (CVSS 9.8) deserialization of untrusted data flaw (CWE-502) enabling remote code execution on on-premises Microsoft SharePoint servers, in its 14 July 2026 security updates. Affected products are SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016; SharePoint Online is not listed as affected. Two web reports describe the bug as exploitable by unauthenticated attackers who send crafted serialized .NET payloads to network-accessible SharePoint endpoints, triggering gadget-chain deserialization and code execution under the privileged SharePoint service account; CERT-EU hedges, calling it 'possibly' exploitable without authentication. Exploitation status evolved: at the 14 July disclosure no active exploitation of this specific CVE had been confirmed, and CISA's SSVC rated exploitation 'none' while judging the attack automatable with total technical impact; on 20 July 2026 WatchTowr published PoC exploit code and reported observing active exploitation, prompting CISA to urge SharePoint hardening. The sources disagree on PoC availability: the 7 September 2026 web report states no public PoC existed and the flaw was not in CISA's KEV catalog at its publication, while CERT-EU's 22 July advisory cites the 20 July WatchTowr PoC; no merged report lists CVE-2026-50522 as added to KEV. The reported EPSS score is 20.346%. The same July cycle also fixed CVE-2026-32201 (CVSS 6.5, spoofing), CVE-2026-45659 (8.8, authenticated RCE), CVE-2026-56164 (9.8, unauthenticated privilege escalation), and CVE-2026-58644 (9.8, unauthenticated RCE); CERT-EU describes this as part of an ongoing wave of exploited on-prem SharePoint flaws. A separate CERT-EU advisory covers the earlier March 2026 wave: CVE-2026-20963 (CVSS 9.8, unauthenticated RCE via deserialization of untrusted data affecting the same SharePoint versions), which Microsoft raised in severity on 17 March 2026 and which entered CISA's Known Exploited Vulnerabilities catalog on 18 March 2026, plus RCEs CVE-2026-26106, CVE-2026-26113, and CVE-2026-26114 fixed in the March 2026 release. If exploited, CVE-2026-50522 enables web shells, credential theft, and lateral movement into Microsoft 365 and Active Directory. Suggested detection: w3wp.exe spawning cmd.exe, powershell.exe, or certutil.exe; new .aspx files in layouts directories; encoded POST payloads. Recommended mitigations across the reports: apply Microsoft's updates promptly,…
- CVE-2026-50522 (CVSS 9.8, CWE-502): remote code execution in on-premises Microsoft SharePoint via deserialization of untrusted data; two web reports describe it as unauthenticated, while CERT-EU calls it 'possibly' exploitable without…
- Mechanism: crafted serialized .NET payloads sent to network-accessible SharePoint endpoints trigger gadget-chain deserialization and RCE under the privileged SharePoint service account.
- Affected products: SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016; SharePoint Online is not listed as affected.
- Patched in Microsoft's 14 July 2026 security updates.
- Exploitation timeline: no exploitation confirmed at the 14 July 2026 disclosure (CISA SSVC rated exploitation 'none', attack automatable, total technical impact); on 20 July 2026 WatchTowr published PoC code and reported observing active…
- Source disagreement: the 7 September 2026 report says no public PoC existed and the CVE was not in CISA's KEV catalog at its publication, while CERT-EU's 22 July 2026 advisory cites the 20 July WatchTowr PoC; no merged report lists…
- EPSS score reported at 20.346% (per the 7 September 2026 report).
- Impact if exploited: web shells, credential theft, and lateral movement into Microsoft 365 and Active Directory.
Coverage timelineoldest first · each row is one article
- · Mar 25, 20262026-004: Critical Vulnerability in SharePoint Exploited
CERT-EU Advisories· 90
CVE-2026-20963 (CVSS 9.8), an unauthenticated RCE in on-prem SharePoint, was added to CISA's KEV on 18 March 2026 and is actively exploited.
- · Jul 22, 20262026-009: Critical Vulnerabilities in Microsoft SharePoint
CERT-EU Advisories· 90
WatchTowr observed active exploitation of SharePoint RCE CVE-2026-50522 (CVSS 9.8), part of an ongoing wave of exploited on-prem SharePoint flaws patched by Microsoft.
- · 8d agoCVE-2026-50522: Microsoft SharePoint Server RCE Vulnerability
Web discovery (articles for new exploits & KEV entries)· 74
CVE-2026-50522 is an unauthenticated .NET deserialization RCE in SharePoint Server Subscription, 2019, and 2016; Microsoft patched it July 14, 2026.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-20963 | Deserialization RCE in Microsoft SharePoint Exploited in the Wild CVE-2026-20963 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint that allows an unauthorized attacker to execute code remotely over the network. The flaw is triggered when SharePoint processes maliciously crafted serialized data without validating it, enabling an attacker to run arbitrary code in the context of the SharePoint service. Successful exploitation gives the attacker code execution on the affected SharePoint server, a foothold that typically supports further lateral movement and data access within the environment. Organizations running affected SharePoint deployments are in scope, though affected version ranges have not yet been published in the available data. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-18, confirming active exploitation, and its EPSS of 31.6% (98th percentile) indicates a high near-term probability of exploitation; no public proof-of-concept is known and CVSS scoring is not yet available. Do: Inventory all SharePoint deployments, prioritize any internet-facing SharePoint Server instances, and apply Microsoft's security updates or vendor-specified mitigations as soon as they are available; federal agencies must follow BOD 22-01 (including cloud services) with its standard remediation timeline, and others should treat KEV inclusion as a patch-now signal despite the absence of a public PoC. Until patched, restrict network exposure of SharePoint and review server logs for signs of untrusted serialized data being processed leading to unexpected code execution. | 9.8 | 33% | KEV |
| massOrder of millions of users across plausibly hundreds of thousands of SharePoint deployments (SharePoint Online and on-prem SharePoint Server) | |
| CVE-2026-26114 +1 in the same advisory: …26106 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 3% |
| — | ||
| CVE-2026-26113 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2026-32201 | Improper Input Validation Spoofing Vulnerability in Microsoft SharePoint Server Microsoft SharePoint Server contains an improper input validation flaw (CWE-20) that can be triggered by an unauthenticated, network-based attacker submitting crafted input to the server. Successful exploitation allows the attacker to perform spoofing over the network, impersonating a trusted user or source within SharePoint; detailed impact mechanics have not been published and no CVSS score or public proof-of-concept is available. Any organization running on-premises Microsoft SharePoint Server is potentially affected, and the available data does not specify affected version ranges. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2026-04-14, indicating evidence of active exploitation, and EPSS assigns a 42.8% probability of exploitation within 30 days (99th percentile). Ransomware association is currently unknown. Do: Apply Microsoft's security updates for SharePoint Server per the vendor advisory as soon as possible, and identify your SharePoint Server versions and builds since specific affected ranges are not provided here. Given the KEV listing, federal agencies must apply the vendor mitigations, follow applicable BOD 22-01 cloud guidance, or discontinue use by the established deadline. Until patched, limit network exposure of SharePoint servers and review authentication and access logs for signs of impersonation or spoofing activity. | 6.5 | 43% | KEV |
| masslikely on the order of 100,000+ on-premises SharePoint Server installations, of which tens of thousands are directly internet-exposed | |
| CVE-2026-45659 | Authenticated Deserialization RCE in Microsoft SharePoint Server (Actively Exploited) CVE-2026-45659 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Microsoft SharePoint Server in which an authorized (authenticated, low-privilege) attacker can submit crafted serialized data over the network, with no user interaction required, to execute code on the server. Successful exploitation carries high impact on confidentiality, integrity, and availability within the SharePoint service context, giving attackers a foothold for follow-on activity, and CISA notes that ransomware use is known. Organizations running on-premises Microsoft SharePoint Server are affected; the source data lists no specific version ranges, and the CPE scope (sharepoint server) points to the on-premises product rather than the Microsoft-managed SharePoint Online service. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-01 after active exploitation, and its EPSS score of 76.1% (100th percentile) indicates a high probability of near-term exploitation. The CVE record lists no public proof-of-concept, though related reporting describes exploitation activity following a public PoC release for a SharePoint authentication bypass. Do: Apply Microsoft's current security updates for SharePoint Server following vendor instructions, prioritizing internet-facing servers, and comply with CISA BOD 26-04, which requires applying mitigations per vendor guidance (including the cited Forensics Triage Requirements) or discontinuing use of the product if mitigations are unavailable. Because in-the-wild exploitation and ransomware use are confirmed, triage exposed servers for compromise: review IIS/SharePoint logs for unexpected authenticated requests, look for webshells or newly modified files in SharePoint web roots, and check for unusual child processes spawned by the SharePoint application pool. Given related reporting on an authentication-bypass PoC, also verify that any related SharePoint authentication-bypass patches are… | 8.8 | 76% | KEV ransomware |
| mass≈100,000 internet-exposed SharePoint Server deployments (order-of-magnitude estimate), with total users across on-premises deployments likely in the millions | |
| CVE-2026-50522 +1 in the same advisory: …58644 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server CVE-2026-50522 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthenticated attacker to send maliciously crafted serialized data over the network and execute code on the server, reflected in its 9.8 critical CVSS score with no privileges or user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, giving attackers a foothold for follow-on actions such as data theft, lateral movement, or ransomware. Any organization running on-premises SharePoint Server is in scope, particularly deployments reachable from untrusted networks; the required action notes stakeholders must evaluate each asset's internet exposure under CISA BOD 26-04. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22 and security news headlines describe it as a critical RCE exploited in the wild, with some reports referencing exploitation after a public proof-of-concept release and an authentication bypass. The structured record lists no public PoC as confirmed, but an EPSS of 84.6% (100th percentile) underscores a very high near-term exploitation likelihood. Do: Apply Microsoft's security updates for SharePoint Server immediately per the vendor advisory, as required under CISA's KEV listing and BOD 26-04, and prioritize any SharePoint deployments that are internet-facing (federal/critical-infrastructure operators must follow BOD 26-04 timelines or discontinue unmitigated use). Until patched, restrict public access to SharePoint endpoints (VPN, firewall rules, or reverse proxy) and review IIS/application logs and running processes for signs of unauthenticated deserialization abuse. Because some reports reference an authentication bypass being chained, also verify authentication paths and monitor for follow-on attacker activity after patching. | 9.8 | 85% | KEV |
| massorder of 100,000+ on-prem SharePoint Server deployments worldwide, with tens of thousands plausibly internet-exposed | |
| CVE-2026-56164 | Missing Authentication in Microsoft SharePoint Server Allows Privilege Escalation Microsoft SharePoint Server contains a missing authentication for critical function vulnerability (CWE-306) that lets an unauthenticated attacker elevate privileges over a network without valid credentials. The flaw is triggered when the affected SharePoint function is accessed remotely without any authentication check, allowing an attacker to gain higher privileges than intended. Successful exploitation could enable an attacker to take elevated actions within the SharePoint environment, potentially leading to further compromise of the server and its data. All organizations running on-premises Microsoft SharePoint Server are potentially affected, though specific versions have not yet been enumerated by Microsoft or CISA. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-14, indicating it is being actively exploited, and its EPSS score of 26.6% (98th percentile) reflects a high near-term exploitation risk. Do: Apply Microsoft's security updates for SharePoint Server as soon as they are available, and check Microsoft's advisory for the specific affected version ranges once published. In the meantime, restrict network access to SharePoint servers, especially for internet-facing instances, and verify whether your environment falls under CISA BOD 26-04 requirements given the KEV listing. Monitor for updated guidance from Microsoft and CISA, as exploitation is confirmed and patching urgency is high. | 9.8 | 27% | KEV |
| masspotentially millions of users and well over 100,000 exposed installations worldwide |