Emergency Security Bulletin: Microsoft SharePoint Remote Code Execution Vulnerability

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-50522 is a critical remote code execution vulnerability affecting supported on-premises Microsoft SharePoint Server products.

The vulnerability results from unsafe deserialization of attacker-controlled data. Successful exploitation may allow an attacker to execute arbitrary code on the SharePoint server, potentially leading to unauthorized access to sensitive information, deployment of malicious components, modification of SharePoint content, disruption of collaboration services, and further compromise of the underlying server.

CISA has added CVE-2026-50522 to its Known Exploited Vulnerabilities (KEV) Catalog, making immediate remediation a priority for organizations operating on-premises SharePoint environments.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Microsoft SharePoint Remote Code Execution Vulnerability


Identifier: CVE-2026-50522
PoC or Exploitation: CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog.  
CVSS Score: 9.8 Critical, CVSS v3.1

Update / Patch:

Affected versions:
 
Microsoft SharePoint Enterprise Server 2016:
  • Builds earlier than 16.0.5561.1001.
 
Microsoft SharePoint Server 2019:
  • Builds earlier than 16.0.10417.20175.
 
Microsoft SharePoint Server Subscription Edition:
  • Builds earlier than 16.0.19725.20434.
 
Fixed versions and updates:
 
SharePoint Server Subscription Edition:
 
  • KB5002882, build 16.0.19725.20434
 
 
SharePoint Server 2019:
 
  • KB5002883, build 16.0.10417.20175
 
 
SharePoint Enterprise Server 2016:
 
  • KB5002891, build 16.0.5561.1001
 
 
 
Official vendor advisory:
 


Description:

CVE-2026-50522 is a deserialization vulnerability in supported on-premises Microsoft SharePoint Server products.
 
Processing attacker-controlled serialized data can result in arbitrary code execution on the SharePoint server.

 

Mitigation Recommendation:

Immediately install the applicable July 2026 SharePoint security updates on every server in each affected farm.
 
Restrict unnecessary internet exposure of on-premises SharePoint servers until remediation is verified.
 
Review SharePoint, IIS, ULS, EDR, and operating-system telemetry for suspicious requests to /_trust/default.aspx, unexpected SharePoint worker-process child processes, unauthorized configuration changes, web shells, or credential and machine-key access.