Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sharepoint_server | 16.0.0, 16.0.0, 16.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft sharepoint server subscription edition | mitre_affected | 90% |
| microsoft | microsoft sharepoint | mitre_affected | 90% |
Added newly discovered vulnerable versions (16.0.5561.1001, 16.0.10417.20175, 16.0.19725.20434) with their corresponding patches, and added CVE-2026-50522 which is confirmed to have active exploitation with public proof-of-concept.
Updated description with unauthenticated attack vector, CISA KEV confirmation, and Microsoft Defender/AMSI detection signatures; clarified affected product versions as SharePoint 2016/2019/Subscription Edition; added CISA-KEV and exploitation confirmation tags.
Updated affected versions and patch availability, added new CWE IDs and CVE tags.
Updated exploit availability to true and noted that the patch was inadvertently left out of the June 2026 release.
Initial creation