LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 22, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 25, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on Jul 22, 2026, with a federal patch deadline of Jul 25, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CVE-2026-50522 is a deserialization of untrusted data vulnerability in Microsoft SharePoint. An unauthorized attacker could use it to execute code over a network. For organizations that run SharePoint, that means a path to full compromise of the application host if the flaw is reachable and unmitigated. Confirm exact product editions, builds, and fixed releases against the vendor advisory before acting.

CISA has directed stakeholders to apply mitigations in line with vendor instructions and BOD 26-04 prioritization and forensics guidance, evaluate internet exposure, and discontinue use if mitigations are unavailable. Ransomware use of this CVE is not documented in the provided facts.

How it works

This issue is classed as CWE-502: deserialization of untrusted data. SharePoint (and similar collaboration platforms) often accept serialized objects in web requests, workflow or service payloads, or other network-facing inputs. When an application deserializes data without adequately restricting type, source, or content, an attacker who can supply or influence that data may cause the runtime to instantiate unexpected types and run attacker-controlled logic.

In practical terms, a remote, unauthorized attacker who can reach the vulnerable SharePoint endpoint may trigger code execution in the context of the SharePoint process. Exact request shape, authentication requirements, and gadget chains are not specified in the provided facts; treat any public proof-of-concept material with caution and validate behavior only in isolated lab conditions against vendor documentation.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed as on-premises server farms, hybrid configurations, or related Microsoft collaboration stacks used for document management, intranet portals, and business workflows. Inventory every host and service that runs SharePoint Server components, including web front ends, application servers, and any internet-facing or partner-facing sites.

How to remediate

Patch first. Apply the Microsoft updates named for CVE-2026-50522 in the official vendor advisory, following your standard change and test process for SharePoint farms (including compatibility checks for custom solutions). Confirm successful installation via build numbers and Microsoft’s verification steps.

If you can't patch immediately

Reduce reachability and monitor aggressively until the vendor fix is installed.

If your data may have been exposed

Actively exploited remote code execution flaws in collaboration platforms frequently lead to web shells, credential theft, and lateral movement into file stores and identity systems. If you have indicators of exploitation or uncertain patch status on an exposed farm, treat the environment as potentially compromised: isolate affected hosts, preserve logs, rotate credentials and secrets that SharePoint could access, and follow your incident response and CISA forensics triage procedures. You can also run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior public dumps while you complete internal investigation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-502
Added to CISA KEVJul 22, 2026
Federal patch deadlineJul 25, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities