Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4137 articles · 226306 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-50522KEVEXPLOITEDPATCHED
microsoft · sharepoint_server

Microsoft SharePoint Remote Code Execution Vulnerability

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Affected Products

VendorProductVersions
microsoftsharepoint_server16.0.0, 16.0.0, 16.0.0

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522(vendor-advisory, patch)

Related News (13 articles)

Tier D
SecurityWeek3h ago
Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
→ No new info (linked only)
Tier D
Heise Security44d ago
Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS
→ No new info (linked only)
Tier D
Help Net Security56d ago
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
→ No new info (linked only)
Tier D
Help Net Security56d ago
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
→ No new info (linked only)
Tier D
BleepingComputer56d ago
Swiss government SharePoint breach compromised 200 accounts
→ No new info (linked only)
Tier B
CERT-FR67d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
Heise Security71d ago
Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke
→ No new info (linked only)
Tier D
Help Net Security72d ago
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
→ No new info (linked only)
Tier B
CERT-FR72d ago
Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)
→ No new info (linked only)
Tier D
The Hacker News72d ago
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
→ No new info (linked only)
Tier B
CERT-FR79d ago
Multiples vulnérabilités dans les produits Microsoft (15 juillet 2026)
→ No new info (linked only)
Tier C
Qualys Blog79d ago
Microsoft and Adobe Patch Tuesday, July 2026 Security Update Review 
→ No new info (linked only)
Tier C
VulDB79d ago
CVE-2026-50522 | Microsoft SharePoint Server deserialization
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
16.0.5556.100516.0.10417.2015316.0.19725.20384
CWECWE-502
PublishedJul 14, 2026
Last enriched71d agov5
Tags
public_pocpatch_tuesday_july_2026machine_key_theftiis_exploitationactive_exploitation_cve_2026_50522public_poc_cve_2026_50522
Trending Score161🔥
Source articles13
Independent8
Info Completeness10/14
Missing: epss, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58644EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 168
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 168
MEDIUMCVE-2026-56164EXPKEV
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Trending: 157
HIGHCVE-2026-63520EXPKEV
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 143
HIGHCVE-2026-65660
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 61

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 14, 2026
Added to CISA KEV
Jul 14, 2026
Discovered by ZDM
Jul 14, 2026
Updated: description
Jul 14, 2026
Updated: tags
Jul 21, 2026
Updated: tags
Jul 22, 2026
Updated: affectedVersions, patchAvailable, tags
Jul 22, 2026
Actively Exploited
Sep 17, 2026
Patch Available
Sep 17, 2026

Version History

v5
Last enriched 71d ago
v5Tier B71d ago

Added new affected versions (16.0.5556.1005, 16.0.10417.20153, 16.0.19725.20384) with lower version thresholds, updated patch versions accordingly, and added tags indicating public PoC and active exploitation of CVE-2026-50522.

affectedVersionspatchAvailabletags
via CERT-FR
v4Tier D72d ago

Updated exploitAvailable to true (public PoC released July 20) and added tags indicating machine key theft and IIS exploitation tactics observed in active attacks.

tags
via Help Net Security
v3Tier D72d ago

Updated exploitAvailable to true due to public PoC release and added tags indicating public exploit availability and Patch Tuesday context.

tags
via The Hacker News
v2Tier C79d ago

Updated description with new details and corrected exploit availability to false.

description
via VulDB
v179d ago

Initial creation