Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5572 articles · 220724 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-50522KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Remote Code Execution Vulnerability

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522(vendor-advisory, patch)

Related News (12 articles)

Tier D
Heise Security34d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier D
Help Net Security45d ago
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
→ No new info (linked only)
Tier D
Help Net Security46d ago
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
→ No new info (linked only)
Tier D
BleepingComputer46d ago
Swiss government SharePoint breach compromised 200 accounts
→ No new info (linked only)
Tier B
CERT-FR57d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Heise Security61d ago
Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke
→ No new info (linked only)
Tier D
Help Net Security62d ago
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
→ No new info (linked only)
Tier B
CERT-FR62d ago
Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)
→ No new info (linked only)
Tier D
The Hacker News62d ago
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
→ No new info (linked only)
Tier B
CERT-FR69d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Qualys Blog69d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier C
VulDB69d ago
CVE-2026-50522 | Microsoft SharePoint Server deserialization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5556.100516.0.10417.2015316.0.19725.20384
CWECWE-502
PublishedJul 14, 2026
Last enriched61d agov5
Tags
public_pocpatch_tuesday_july_2026machine_key_theftiis_exploitationactive_exploitation_cve_2026_50522public_poc_cve_2026_50522
Trending Score1
Source articles12
Independent7
Info Completeness10/14
Missing: epss, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-85880EXPKEV
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Trending: 55
HIGHCVE-2026-66804
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
Trending: 49
MEDIUMCVE-2026-55945EXP
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Trending: 44
CRITICALCVE-2026-70352
Azure AI Language Elevation of Privilege Vulnerability
Trending: 44
HIGHCVE-2026-88097
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description
Jul 14, 2026
Updated: tags
Jul 21, 2026
Updated: tags
Jul 22, 2026
Updated: affectedVersions, patchAvailable, tags
Jul 22, 2026
Actively Exploited
Sep 17, 2026
Patch Available
Sep 17, 2026

Version History

v5
Last enriched 61d ago
v5Tier B61d ago

Added new affected versions (16.0.5556.1005, 16.0.10417.20153, 16.0.19725.20384) with lower version thresholds, updated patch versions accordingly, and added tags indicating public PoC and active exploitation of CVE-2026-50522.

affectedVersionspatchAvailabletags
via CERT-FR
v4Tier D61d ago

Updated exploitAvailable to true (public PoC released July 20) and added tags indicating machine key theft and IIS exploitation tactics observed in active attacks.

tags
via Help Net Security
v3Tier D62d ago

Updated exploitAvailable to true due to public PoC release and added tags indicating public exploit availability and Patch Tuesday context.

tags
via The Hacker News
v2Tier C69d ago

Updated description with new details and corrected exploit availability to false.

description
via VulDB
v169d ago

Initial creation