AllCyberNews

CVE-2026-50522

Microsoft SharePoint Remote Code Execution Vulnerability

CVSS 9.8 critical · Microsoft Microsoft SharePoint Enterprise Server 2016 · published 2026-07-14

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Coverage 2 sources

  1. 2026-07-22 Help Net Security critical Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

    CVE-2026-50522 SharePoint RCE is being actively exploited to steal IIS machine keys.

  2. 2026-07-22 CISA Cybersecurity Advisories critical CISA Adds Two Known Exploited Vulnerabilities to Catalog

    CISA added two exploited vulnerabilities to its KEV Catalog: CVE-2026-16232 in Check Point SmartConsole and CVE-2026-50522 in Microsoft SharePoint.

Mentioned with

CVE-2026-16232

Also covered