CVE-2026-50522

CRITICAL KEV

Microsoft SharePoint Remote Code Execution Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-50522 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 6 public exploits from researchers including WismanSec, webshellseo8, darses.

AI-analyzed exploit summary This repository contains functional exploit code for CVE-2026-50522, a deserialization vulnerability in SharePoint's `/_trust` endpoint that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken cookies. The PoC demonstrates both information leakage (machine key extraction) and command execution using ysoserial.net gadgets.

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Exploits (6)

github WORKING POC
by WismanSec · htmlremote
https://github.com/WismanSec/sharepoint-2026-poc

This repository contains functional exploit code for CVE-2026-50522, a deserialization vulnerability in SharePoint's `/_trust` endpoint that allows remote attackers to dump machine keys or achieve RCE via crafted SecurityContextToken cookies. The PoC demonstrates both information leakage (machine key extraction) and command execution using ysoserial.net gadgets.

Classification
Working Poc 99%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint (2026 versions, likely patched in later updates)
No auth needed
Prerequisites: Access to SharePoint `/_trust/default.aspx` endpoint · ysoserial.net executable (for gadget generation) · Target must not have AMSI request-body scanning enabled for `/_trust`
mistral-large-3 · analyzed Aug 07, 2026 Full analysis →
nomisec SUSPICIOUS
by webshellseo8 · poc
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept

This repository claims to be a PoC for CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server, but contains no technical details or exploit code. It directs users to an external Telegram channel for the 'complete PoC,' which is a common social engineering tactic.

Classification
Suspicious 98%
Attack Type
Deserialization
Complexity
Unknown
Reliability
Unknown
Target: Microsoft SharePoint Server
No auth needed
mistral-large-3 · analyzed Jul 29, 2026 Full analysis →
nomisec SUSPICIOUS
by darses · remote
https://github.com/darses/CVE-2026-50522

The repository contains HTTP request logs with malformed WS-Trust SAML token payloads targeting Microsoft SharePoint or ADFS endpoints. The payloads include obfuscated binary data in XML cookies, but no functional exploit code or technical analysis is provided. The DLLs in the payloads directory appear to be randomly named and lack context or source code.

Classification
Suspicious 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft SharePoint or ADFS (unspecified version)
No auth needed
Prerequisites: Access to a vulnerable SharePoint or ADFS endpoint · Ability to send crafted WS-Trust SAML token requests
mistral-large-3 · analyzed Jul 29, 2026 Full analysis →
github WRITEUP
by ChPratik · poc
https://github.com/ChPratik/CVE-2026-50522

This repository contains a detailed technical writeup of CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server leading to remote code execution (RCE). The analysis includes root cause (unsafe deserialization in `SessionSecurityTokenHandler`), affected versions, patch details, exploitation mechanics, and defensive guidance, but does not include exploit code.

Classification
Writeup 99%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on-premises)
No auth needed
Prerequisites: Network reachability to vulnerable SharePoint server · Unpatched SharePoint version (pre-July 2026 updates)
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →
github WORKING POC
by 4minx · c#remote
https://github.com/4minx/CVE-2026-50522

This repository provides a functional exploit for CVE-2026-50522, a deserialization vulnerability in SharePoint that allows remote code execution via crafted WS-Trust requests. The exploit uses ysoserial to generate malicious payloads targeting the BinaryFormatter deserialization gadget, with options for OOB callback verification and webshell deployment.

Classification
Working Poc 98%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint (unspecified version, likely 2019/SE)
No auth needed
Prerequisites: Network access to SharePoint server · ysoserial.exe tool (included in repo) · OOB callback server (e.g., Burp Collaborator, Interact.sh)
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github STUB
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-50522

This repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-50522. It only includes a README with generic setup instructions, legal disclaimers, and a reference to an external script via curl command.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Jul 22, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

Scores

CVSS v3 9.8
EPSS 0.7698
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-22
VulnCheck KEV 2026-07-20
ENISA EUVD EUVD-2026-43767
CWE
CWE-502
Status published
Products (6)
Microsoft/Microsoft SharePoint Enterprise Server 2016 16.0.0 - 16.0.5561.1001
Microsoft/Microsoft SharePoint Server 2019 16.0.0 - 16.0.10417.20175
Microsoft/Microsoft SharePoint Server Subscription Edition 16.0.0 - 16.0.19725.20434
microsoft/sharepoint_server 2016
microsoft/sharepoint_server 2019
microsoft/sharepoint_server < 16.0.19725.20434
Published Jul 14, 2026
KEV Added Jul 22, 2026
Tracked Since Jul 14, 2026