6 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-50522 is a critical remote code execution vulnerability affecting supported on-premises Microsoft SharePoint Server products.
The vulnerability results from unsafe deserialization of attacker-controlled data. Successful exploitation may allow an attacker to execute arbitrary code on the SharePoint server, potentially leading to unauthorized access to sensitive information, deployment of malicious components, modification of SharePoint content, disruption of collaboration services, and further compromise of the underlying server.
CISA has added CVE-2026-50522 to its Known Exploited Vulnerabilities (KEV) Catalog, making immediate remediation a priority for organizations operating on-premises SharePoint environments.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Microsoft SharePoint Remote Code Execution Vulnerability
Identifier: CVE-2026-50522
PoC or Exploitation: CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog.
CVSS Score: 9.8 Critical, CVSS v3.1
Update / Patch:
- Builds earlier than 16.0.5561.1001.
- Builds earlier than 16.0.10417.20175.
- Builds earlier than 16.0.19725.20434.
- KB5002882, build 16.0.19725.20434
- KB5002883, build 16.0.10417.20175
- KB5002891, build 16.0.5561.1001
Description:
Mitigation Recommendation: