← back

CVE-2026-50522

CRITICAL · 9.8 KEV EPSS 75.8%
hype LIKELY HACK · 82 hack

Working PoC public, confirmed active exploitation, defender guidance specific, no KEV yet.

What: Unauthenticated deserialization in Microsoft Office SharePoint on-premises (2016, 2019, Subscription Edition) allows remote code execution; CVSS 9.8 CRITICAL, EPSS 0.97.

Why it matters: Social chatter confirms active in-the-wild exploitation with public PoC within 24 hours of posts. WatchTowr and defender reports document attackers stealing IIS machine keys for persistence—a post-patch persistence vector. No KEV listing yet, but urgency and specificity suggest real triage activity.

Where it's seen: Security news outlets (HelpNetSecurity, TheHackerNews), threat intel feeds, defender alerts emphasizing machine key rotation. Posts span multiple languages and regions, indicating broad awareness and coordinated response.

RISK: CRITICAL — Unauthenticated RCE, active exploitation, public PoC, persistence via machine key theft.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 7/22/2026, 1:43:08 PM

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected versions

  • microsoft/sharepoint_server
    • < 16.0.19725.20434
    • 2016
    • 2019

Weaknesses

Vendors

  • microsoft

Products

  • sharepoint_server