CVE-2026-50522
CRITICAL · 9.8 KEV EPSS 75.8%Working PoC public, confirmed active exploitation, defender guidance specific, no KEV yet.
What: Unauthenticated deserialization in Microsoft Office SharePoint on-premises (2016, 2019, Subscription Edition) allows remote code execution; CVSS 9.8 CRITICAL, EPSS 0.97.
Why it matters: Social chatter confirms active in-the-wild exploitation with public PoC within 24 hours of posts. WatchTowr and defender reports document attackers stealing IIS machine keys for persistence—a post-patch persistence vector. No KEV listing yet, but urgency and specificity suggest real triage activity.
Where it's seen: Security news outlets (HelpNetSecurity, TheHackerNews), threat intel feeds, defender alerts emphasizing machine key rotation. Posts span multiple languages and regions, indicating broad awareness and coordinated response.
RISK: CRITICAL — Unauthenticated RCE, active exploitation, public PoC, persistence via machine key theft.
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Affected versions
- microsoft/sharepoint_server
- < 16.0.19725.20434
- 2016
- 2019