CISA Adds SharePoint RCE CVE-2026-50522 to KEV, Orders Fixes by July 25
Updated
Updated · The Hacker News · Jul 23
CISA Adds SharePoint RCE CVE-2026-50522 to KEV, Orders Fixes by July 25
3 articles · Updated · The Hacker News · Jul 23
Summary
July 22 saw CISA add CVE-2026-50522 to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until July 25 to patch the critical SharePoint flaw.
WatchTowr said attackers began actively exploiting the bug after a public proof-of-concept appeared, using a single request to pull SharePoint machine keys and keep persistent access.
Microsoft scored the deserialization flaw at 9.8 and said it can enable remote code execution over the network; Defused Cyber reported requests hitting a SharePoint sign-in endpoint without authentication material.
CVE-2026-50522 is the third SharePoint Server bug under active exploitation this month, alongside CVE-2026-56164 and CVE-2026-58644, as CISA warns multiple on-premises SharePoint versions face key theft, persistence and malware deployment.