CVE-2026-50522
CRITICAL KEVMicrosoft SharePoint Remote Code Execution Vulnerability
Title source: cnaExploitation Summary
CVE-2026-50522 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 6 public exploits from researchers including WismanSec, webshellseo8, darses.
AI-analyzed exploit summary This repository contains functional exploit code for CVE-2026-50522, a deserialization vulnerability in SharePoint's `/_trust` endpoint that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken cookies. The PoC demonstrates both information leakage (machine key extraction) and command execution using ysoserial.net gadgets.
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Exploits (6)
This repository contains functional exploit code for CVE-2026-50522, a deserialization vulnerability in SharePoint's `/_trust` endpoint that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken cookies. The PoC demonstrates both information leakage (machine key extraction) and command execution using ysoserial.net gadgets.
This repository claims to be a PoC for CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server, but contains no technical details or exploit code. It directs users to an external Telegram channel for the 'complete PoC,' which is a common social engineering tactic.
The repository contains HTTP request logs with malformed WS-Trust SAML token payloads targeting Microsoft SharePoint or ADFS endpoints. The payloads include obfuscated binary data in XML cookies, but no functional exploit code or technical analysis is provided. The DLLs in the payloads directory appear to be randomly named and lack context or source code.
This repository contains a detailed technical writeup of CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server leading to remote code execution (RCE). The analysis includes root cause (unsafe deserialization in `SessionSecurityTokenHandler`), affected versions, patch details, exploitation mechanics, and defensive guidance, but does not include exploit code.
This repository provides a functional exploit for CVE-2026-50522, a deserialization vulnerability in SharePoint that allows remote code execution via crafted WS-Trust requests. The exploit uses ysoserial to generate malicious payloads targeting the BinaryFormatter deserialization gadget, with options for OOB callback verification and webshell deployment.
This repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-50522. It only includes a README with generic setup instructions, legal disclaimers, and a reference to an external script via curl command.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H