Latest publications of type Security AdvisoriesRead More
Release Date:
Critical Vulnerability in Microsoft SharePoint
Download
-
Download PDF
MD5
SHA-1
SHA-256
SHA-512
-
Download MARKDOWN
-
Download JSON
History:
- 22/07/2026 — v1.0 — Initial publication
Summary
On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code, and later, successful exploitation attempts [2].
CERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.
Technical Details
The vulnerability CVE-2026-50522, with a CVSS score of 9.8, is a critical deserialisation vulnerability in Microsoft SharePoint. It allows a remote attacker to execute code on the affected assets.
While Microsoft suggests this vulnerability requires some level of authentication [1], recent findings may indicate otherwise [2, 3].
Affected Products
This vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 [1].
CERT-EU strongly recommends to update affected servers as soon as possible, and to run compromise assessment to identify potentially affected SharePoint instances.
CERT-EU also recommends to rotate credentials on any assets that may have been vulnerable and exposed on the internet.
Considering the number of recent critical RCE vulnerability affecting SharePoint, exposing any SharePoint server on the internet should be reconsidered.
References
[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
Share this publication
On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code, and later, successful exploitation attempts.
CERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.