Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-50522

Published 2026-07-14
Updated 2 months ago
Vendor/s
Microsoft
Product/s
SharePoint
Version/s
* > 16.0.19725.20434
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical 9.8 RCE vulnerability in Microsoft SharePoint Server. Actively exploited; immediate patching required for versions prior to 16.0.19725.20434.

CPE

Microsoft logo
Microsoft
Product Version Start Version End (excl.) Status
sharepoint_server * 16.0.19725.20434 vulnerable
sharepoint_server 2016 2016 vulnerable
sharepoint_server 2019 2019 vulnerable

Related weakness (CWE)

CWE-502

Remediation plan

1

Apply official patches

Immediately download and install the security updates provided by Microsoft for SharePoint Server to address the underlying deserialization flaw.

2

Update affected systems

Ensure all SharePoint Server instances are updated to version 16.0.19725.20434 or later, specifically targeting vulnerable SharePoint Server 2016 and 2019 deployments.

3

Restrict access

Minimize the attack surface by placing SharePoint servers behind a Web Application Firewall (WAF) and restricting management interface access to authorized internal IP addresses only.

4

Monitor for exploitation

Implement forensic triage requirements as per CISA BOD 26-04 and scan for indicators of compromise, such as unauthorized web shells or suspicious process execution.

Detection Guidance

"Monitor web server logs for anomalous POST requests targeting SharePoint service endpoints. Use EDR solutions to alert on suspicious child processes spawned by the SharePoint worker process (w3wp.exe), such as cmd.exe or powershell.exe. Additionally, deploy network-based signatures to detect common .NET deserialization gadgets and payloads within incoming traffic, and audit SharePoint ULS logs for serialization-related errors or unexpected type loading."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management