type: cve ยท created: 2026-07-22 ยท updated: 2026-07-22 ยท tags: [cve, zero-day, kev, rce, deserialization, microsoft] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true
CVE-2026-50522 โ Critical SharePoint Server RCE
CVE-2026-50522 is a critical deserialisation vulnerability in Microsoft SharePoint Server, rated CVSS 9.8, that allows authenticated Site Owners to execute arbitrary code remotely. It was disclosed in the July 2026 Patch Tuesday updates.
Status: Active Exploitation
- Public PoC released in July 2026
- Active exploitation confirmed by watchTowr researchers
- CISA urges organisations to harden SharePoint deployments immediately
- Third SharePoint flaw from July 2026 Patch Tuesday under active exploitation
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-50522 |
| CVSS | 9.8 (Critical) |
| Type | Deserialisation โ Remote Code Execution |
| Privilege | Requires authenticated Site Owner |
| Product | Microsoft SharePoint Server |
| Disclosure | July 2026 Patch Tuesday |
| PoC | Public โ published shortly after patch release |
| Active exploitation | Confirmed by watchTowr |
Australian Significance
SharePoint is widely deployed across Australian government agencies and enterprises. With CISA urging immediate hardening, Australian organisations should prioritise patching. The ACSC has previously issued guidance on securing Microsoft SharePoint deployments (see Acsc Cms Exploitation for related CMS hardening context).
Mitigation
- Apply Microsoft's July 2026 Patch Tuesday updates immediately
- Review and restrict Site Owner privileges to least-privilege principle
- Monitor for post-exploitation activity consistent with SharePoint compromise
- Follow CISA's SharePoint hardening guidance
Related Pages
- Wp2Shell โ WordPress unauthenticated RCE (CVE-2026-63030 + CVE-2026-60137)
- Cve 2026 6875 Servicenow Ai โ ServiceNow AI Platform sandbox escape (CVSS 9.5)