CVE-2026-50522

CRITICAL KEV

Microsoft SharePoint Remote Code Execution Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-50522 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 3 public exploits from researchers including ChPratik, 4minx, HORKimhab.

AI-analyzed exploit summary This repository contains a detailed technical writeup of CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server leading to remote code execution (RCE). The analysis includes root cause (unsafe deserialization in `SessionSecurityTokenHandler`), affected versions, patch details, exploitation mechanics, and defensive guidance, but does not include exploit code.

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Exploits (3)

github WRITEUP
by ChPratik · poc
https://github.com/ChPratik/CVE-2026-50522

This repository contains a detailed technical writeup of CVE-2026-50522, a critical deserialization vulnerability in Microsoft SharePoint Server leading to remote code execution (RCE). The analysis includes root cause (unsafe deserialization in `SessionSecurityTokenHandler`), affected versions, patch details, exploitation mechanics, and defensive guidance, but does not include exploit code.

Classification
Writeup 99%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on-premises)
No auth needed
Prerequisites: Network reachability to vulnerable SharePoint server · Unpatched SharePoint version (pre-July 2026 updates)
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →
github WORKING POC
by 4minx · c#remote
https://github.com/4minx/CVE-2026-50522

This repository provides a functional exploit for CVE-2026-50522, a deserialization vulnerability in SharePoint that allows remote code execution via crafted WS-Trust requests. The exploit uses ysoserial to generate malicious payloads targeting the BinaryFormatter deserialization gadget, with options for OOB callback verification and webshell deployment.

Classification
Working Poc 98%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Microsoft SharePoint (unspecified version, likely 2019/SE)
No auth needed
Prerequisites: Network access to SharePoint server · ysoserial.exe tool (included in repo) · OOB callback server (e.g., Burp Collaborator, Interact.sh)
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
github STUB
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-50522

This repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-50522. It only includes a README with generic setup instructions, legal disclaimers, and a reference to an external script via curl command.

Classification
Stub 95%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Jul 22, 2026 Full analysis →

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory patch
Microsoft SharePoint Remote Code Execution Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

Scores

CVSS v3 9.8
EPSS 0.5710
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-22
VulnCheck KEV 2026-07-20
ENISA EUVD EUVD-2026-43767
CWE
CWE-502
Status published
Products (6)
Microsoft/Microsoft SharePoint Enterprise Server 2016 16.0.0 - 16.0.5561.1001
Microsoft/Microsoft SharePoint Server 2019 16.0.0 - 16.0.10417.20175
Microsoft/Microsoft SharePoint Server Subscription Edition 16.0.0 - 16.0.19725.20434
microsoft/sharepoint_server 2016
microsoft/sharepoint_server 2019
microsoft/sharepoint_server < 16.0.19725.20434
Published Jul 14, 2026
KEV Added Jul 22, 2026
Tracked Since Jul 14, 2026