CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Summary
A deserialization of untrusted data vulnerability (CVE-2026-50522) has been identified in Microsoft SharePoint, potentially allowing remote code execution by unauthorized attackers. Organizations are instructed to apply vendor mitigations and comply with CISA's directives on prioritizing security updates, with a federal due date of July 25, 2026.
IFF Assessment
This vulnerability allows an unauthorized attacker to execute code over a network, posing a direct threat to system integrity and data confidentiality.
Severity
This is an estimation based on the description of 'deserialization of untrusted data' and 'execute code over a network,' which typically implies a high severity, remote code execution vulnerability. The CVSS v3.1 base score for such vulnerabilities often falls in the critical range (9.0-10.0), considering factors like attack vector (Network), attack complexity (Low), privileges required (None), user interaction (None), scope (Changed), confidentiality, integrity, and availability impacts.
CISA KEV: Listed as actively exploited. Federal patch due: July 25, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching or mitigating this critical deserialization vulnerability in Microsoft SharePoint to prevent potential remote code execution. Adherence to CISA's guidance on risk-based prioritization and timely patching is crucial, especially given the federal due date. Monitoring for any exploitation attempts or known ransomware use associated with this CVE is also paramount.