Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4357 articles · 196326 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-50522KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Remote Code Execution Vulnerability

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522(vendor-advisory, patch)

Related News (12 articles)

Tier D
Heise Security4d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier D
Help Net Security16d ago
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
→ No new info (linked only)
Tier D
Help Net Security16d ago
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
→ No new info (linked only)
Tier D
BleepingComputer17d ago
Swiss government SharePoint breach compromised 200 accounts
→ No new info (linked only)
Tier B
CERT-FR28d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Heise Security31d ago
Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke
→ No new info (linked only)
Tier D
Help Net Security32d ago
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
→ No new info (linked only)
Tier B
CERT-FR33d ago
Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)
→ No new info (linked only)
Tier D
The Hacker News33d ago
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
→ No new info (linked only)
Tier B
CERT-FR40d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Qualys Blog40d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier C
VulDB40d ago
CVE-2026-50522 | Microsoft SharePoint Server deserialization
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5556.100516.0.10417.2015316.0.19725.20384
CWECWE-502
PublishedJul 14, 2026
Last enriched32d agov5
Tags
public_pocpatch_tuesday_july_2026machine_key_theftiis_exploitationactive_exploitation_cve_2026_50522public_poc_cve_2026_50522
Trending Score80
Source articles12
Independent7
Info Completeness10/14
Missing: epss, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-69836EXPKEV
Microsoft Entra ID Remote Code Execution Vulnerability
Trending: 129
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 87
HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 73
HIGHCVE-2026-45586EXPKEV
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Trending: 65
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 60

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description
Jul 14, 2026
Updated: tags
Jul 21, 2026
Updated: tags
Jul 22, 2026
Updated: affectedVersions, patchAvailable, tags
Jul 22, 2026
Actively Exploited
Aug 20, 2026
Patch Available
Aug 20, 2026

Version History

v5
Last enriched 32d ago
v5Tier B32d ago

Added new affected versions (16.0.5556.1005, 16.0.10417.20153, 16.0.19725.20384) with lower version thresholds, updated patch versions accordingly, and added tags indicating public PoC and active exploitation of CVE-2026-50522.

affectedVersionspatchAvailabletags
via CERT-FR
v4Tier D32d ago

Updated exploitAvailable to true (public PoC released July 20) and added tags indicating machine key theft and IIS exploitation tactics observed in active attacks.

tags
via Help Net Security
v3Tier D33d ago

Updated exploitAvailable to true due to public PoC release and added tags indicating public exploit availability and Patch Tuesday context.

tags
via The Hacker News
v2Tier C40d ago

Updated description with new details and corrected exploit availability to false.

description
via VulDB
v140d ago

Initial creation