Critical Vulnerability CVE-2026-50522 in Microsoft SharePoint Server Under Exploitation
Successful exploitation of CVE-2026-50522 could allow an unauthenticated attacker to execute code remotely
Summary
Successful exploitation of CVE-2026-50522 could allow an unauthenticated attacker to execute code remotely
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-50522
Security researchers have reported exploitation of CVE-2026-50522, and a public proof-of-concept exploit is available. In successful exploitation attempts, attackers have been observed obtaining SharePoint Server machine keys via a single request.
The NHS England National CSOC assesses further exploitation as likely.
SharePoint Server 2016 and 2019 are no longer supported
As of 14 July 2026, Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are strongly encouraged to switch to a supported version
Introduction
Microsoft has released security updates to address a critical vulnerability affecting on-premises deployments of Microsoft SharePoint Server. Successful exploitation could allow an unauthenticated attacker to execute code remotely.
- CVE-2026-50522 - Deserialisation of Untrusted Data vulnerability - CVSSv3 score: 9.8
NHS Organisations Must Complete CC-4816 and CC-4818 in RtaNCA
NHS England issued High Severity Cyber Alert (HSA) CC-4816 on Monday 20 July 2026 to address CVE-2026-58644. This alert covers CVE-2026-50522, which is a different vulnerability with different remediation actions.
Completing the remediation actions detailed in this alert will also remediate CVE-2026-58644 (CC-4816), allowing both cyber alerts to be marked as "complete" in the Respond to an NHS Cyber Alert (RtaNCA) portal. The remediation actions detailed in CC-4816 do not remediate CVE-2026-50522 (this alert).
Remediation advice
Affected organisations must review Microsoft's security advisory for CVE-2026-50522 and follow the remediation steps below.
Applying the "Remediation Steps" detailed below will remediate both CVE-2026-58644 (from CC-4816) and CVE-2026-50522 (this alert). Organisations must update SharePoint Server appliances to one of the versions detailed below or later.
Remediation steps
| Type | Step |
|---|---|
| Patch |
Required: Patch to a fixed version Organisations must update on-premises deployments of Microsoft SharePoint Server to the latest version available. Fixed releases include:
Note: SharePoint Server 2016 and 2019 are no longer supported. Organisations should migrate to a supported version. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522 |
| Action |
Required: Rotate credentials on internet-facing SharePoint Servers Observed exploitation of CVE-2026-50522 has involved attackers obtaining SharePoint machine keys via a single request. Organisations must rotate credentials on any internet-facing SharePoint Servers. If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 22 July 2026 11:56 am