Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-22 ยท updated: 2026-07-22 ยท tags: [cve, zero-day, kev, rce, deserialization, microsoft] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, healthcare, finance] ยท au_impact: true

CVE-2026-50522 โ€” Critical SharePoint Server RCE

CVE-2026-50522 is a critical deserialisation vulnerability in Microsoft SharePoint Server, rated CVSS 9.8, that allows authenticated Site Owners to execute arbitrary code remotely. It was disclosed in the July 2026 Patch Tuesday updates.

Status: Active Exploitation

  • Public PoC released in July 2026
  • Active exploitation confirmed by watchTowr researchers
  • CISA urges organisations to harden SharePoint deployments immediately
  • Third SharePoint flaw from July 2026 Patch Tuesday under active exploitation

Vulnerability Details

Attribute Detail
CVE CVE-2026-50522
CVSS 9.8 (Critical)
Type Deserialisation โ†’ Remote Code Execution
Privilege Requires authenticated Site Owner
Product Microsoft SharePoint Server
Disclosure July 2026 Patch Tuesday
PoC Public โ€” published shortly after patch release
Active exploitation Confirmed by watchTowr

Australian Significance

SharePoint is widely deployed across Australian government agencies and enterprises. With CISA urging immediate hardening, Australian organisations should prioritise patching. The ACSC has previously issued guidance on securing Microsoft SharePoint deployments (see Acsc Cms Exploitation for related CMS hardening context).

Mitigation

  1. Apply Microsoft's July 2026 Patch Tuesday updates immediately
  2. Review and restrict Site Owner privileges to least-privilege principle
  3. Monitor for post-exploitation activity consistent with SharePoint compromise
  4. Follow CISA's SharePoint hardening guidance

Related Pages