🔴 Critical | Source: CISA Known Exploited Vulnerabilities
A critical deserialization vulnerability in Microsoft SharePoint (CVE-2026-50522) allows an unauthenticated remote attacker to execute arbitrary code over a network without any user interaction. Deserialization flaws of this type are notoriously dangerous as they can be exploited to gain full control of affected servers. CISA has added this to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.
Security Architect’s Take: Patch affected SharePoint instances immediately — CISA’s remediation deadline is 25 July 2026, but given active exploitation you should treat this as urgent. If immediate patching is not possible, consider restricting network access to SharePoint servers, enforcing allowlisting at the perimeter, and reviewing logs for anomalous deserialization activity or unexpected process spawning from SharePoint worker processes.
Original advisory: CVE-2026-50522: Microsoft SharePoint