Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild

In Cybersecurity News - Original News Source is cybersecuritynews.com by Blog Writer

Spread the love

A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers.

The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a bug class that has repeatedly plagued SharePoint in 2026.

CVE-2026-50522 affects on-premises x64 deployments of Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

An attacker can send a specially crafted serialized object to a vulnerable endpoint without prior authentication or user interaction, triggering arbitrary code execution in the SharePoint server’s context.

Successful exploitation can lead to full server takeover, deployment of web shells, theft of application secrets, and use of the compromised host as a foothold for lateral movement across the network.

Notably, the same July 2026 patch cycle addressed a companion flaw, CVE-2026-58644, which requires an attacker to already hold at least Site Owner permissions to inject and execute code, distinguishing it from the fully unauthenticated CVE-2026-50522.

Microsoft has confirmed active in-the-wild exploitation of CVE-2026-58644, while CVE-2026-50522 itself is not currently confirmed as exploited, though its EPSS score of roughly 19.7% signals a meaningful near-term risk.

Defused researchers monitoring honeypot traffic during the current SharePoint attack wave have observed an undocumented .NET deserialization payload targeting SharePoint sign-in endpoints, with request fingerprints carrying no authentication material.

This pattern aligns more closely with the unauthenticated profile of CVE-2026-50522 than with the Site Owner-gated CVE-2026-58644, prompting analysts to reassess the activity as likely tied to CVE-2026-50522 rather than an unrelated zero-day.

Independent tracking from Check Point and Censys corroborates that both CVEs were published together and patched in the same July 2026 update, with over 10,000 internet-facing SharePoint servers still exposed globally.

Affected Versions and Fixes

Product Vulnerable Prior To Notes
SharePoint Enterprise Server 2016 16.0.5561.1001 KB applies to both Server 2016 and Enterprise Server 2016
SharePoint Server 2019 16.0.10417.20175 Requires the July 2026 cumulative update
SharePoint Server Subscription Edition 16.0.19725.20434 Latest supported branch

Takeaway for Defenders

  • Apply Microsoft’s July 2026 security update immediately across all SharePoint farm members, since inconsistent patching leaves gaps for lateral exploitation.
  • Retire or upgrade unsupported SharePoint deployments that cannot receive the fix.
  • Monitor for anomalous requests to sign-in and authentication endpoints, particularly unauthenticated .NET deserialization payloads that don’t match published proof-of-concept traffic.
  • Restrict internet exposure of on-premises SharePoint servers where feasible, given Shadowserver’s tally of thousands of exposed instances.
  • Review CISA’s Known Exploited Vulnerabilities catalog, which already lists the paired CVE-2026-58644 as actively exploited under Binding Operational Directive requirements.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment