CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jul 22, 2026
- US federal agencies must remediate it by Jul 25, 2026 (BOD 22-01)
- First attack observed 5 days after disclosure
- Confirmed by sensors, not only by reports
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Source: CISA KEV · Sep 8, 2026 Sep 7, 2026 Sep 6, 2026 Sep 5, 2026 Sep 4, 2026 Sep 3, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| microsoft | sharepoint server | < 16.0.19725.20434 |
Related articles
RansomwareCritical Alert: Cl0p Ransomware Targets PTC Windchill and FlexPLM with a Vulnerability Chain
On July 25, 2026, the industrial security landscape was shaken by a new aggressive campaign from the Cl0p ransomware group also known as Chubby Scorpius,
VulnerabilitiesCyber Threats and Offensive AI: The Landscape as of July 26, 2026
Explore the July 2026 cyber threat landscape: critical software vulnerabilities, ransomware, and state-sponsored attacks leveraging offensive AI.
VulnerabilitiesFour Critical Vulnerabilities Exploited Against macOS, SharePoint, VMware vCenter, and Windows
CISA has added four actively exploited critical vulnerabilities to its Known Exploited Vulnerabilities KEV catalog. The flaws affect Apple macOS,
VulnerabilitiesCVE-2026-69836: Critical Vulnerability Exploited in Microsoft Entra ID, but Customers Need Take No Action
Microsoft fixes critical CVE-2026-69836 in Entra ID, fully mitigated. No patches needed. Exploited in attacks but resolved.
VulnerabilitiesBTR Reforged: Microsoft Defender’s Driver Can Be Weaponized Against Windows Security
BTR Reforged: Abusing Defender's driver to bypass Windows security. Requires admin access, affects Windows 7-11. Presented at Black Hat 2026.
VulnerabilitiesAmazon Kiro: a prompt injection exfiltrates data from the workspace with a single message
Researchers reveal a prompt injection flaw in Amazon Kiro that exfiltrates workspace data via a single message. Affects IDE versions, patched in update.
VulnerabilitiesGit Turned into a Trap: Seven AI Agents Can Execute Code from Repositories
Seven AI coding agents execute attacker code via malicious Git core.fsmonitor config when auto-running git status, bypassing trust and sandbox controls.
VulnerabilitiesFalconFlank: PoC Released for Privilege Escalation in CrowdStrike Falcon
FalconFlank PoC targets CrowdStrike Falcon Sensor privilege escalation via Office macro remediation on Windows 11 25H2 and Server 2025. No CVE yet.
VulnerabilitiesMicrosoft Fixes 398 Vulnerabilities as Exploited Windows Kernel Flaw Enters CISA KEV
Microsoft patched 398 vulnerabilities, including exploited Windows kernel flaw CVE-2026-68820 now in CISA KEV. Patch immediately.
VulnerabilitiesMicrosoft Patches 966 Flaws as Two Windows Zero-Days Come Under Active Attack
Microsoft fixed 966 flaws in record September Patch Tuesday, including two exploited Windows privilege-escalation zero-days leading to SYSTEM access.
APTBlueMoon Exploit Kit Gives Four Espionage Groups a Shared Chrome-to-Windows Attack Chain
Four espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.
This product uses the NVD API but is not endorsed or certified by the NVD.