Skip to main content

Critical Vulnerability CVE-2026-50522 in Microsoft SharePoint Server Under Exploitation

Successful exploitation of CVE-2026-50522 could allow an unauthenticated attacker to execute code remotely

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Successful exploitation of CVE-2026-50522 could allow an unauthenticated attacker to execute code remotely


Threat details

Exploitation of CVE-2026-50522

Security researchers have reported exploitation of CVE-2026-50522, and a public proof-of-concept exploit is available. In successful exploitation attempts, attackers have been observed obtaining SharePoint Server machine keys via a single request.

The NHS England National CSOC assesses further exploitation as likely.

SharePoint Server 2016 and 2019 are no longer supported

As of 14 July 2026, Microsoft's extended support for SharePoint Server 2016 and SharePoint Server 2019 has come to an end, therefore these products are now unsupported by Microsoft. Organisations are strongly encouraged to switch to a supported version


Introduction

Microsoft has released security updates to address a critical vulnerability affecting on-premises deployments of Microsoft SharePoint Server. Successful exploitation could allow an unauthenticated attacker to execute code remotely.

  • CVE-2026-50522 - Deserialisation of Untrusted Data vulnerability - CVSSv3 score: 9.8

NHS Organisations Must Complete CC-4816 and CC-4818 in RtaNCA

NHS England issued High Severity Cyber Alert (HSA) CC-4816 on Monday 20 July 2026 to address CVE-2026-58644. This alert covers CVE-2026-50522, which is a different vulnerability with different remediation actions.

Completing the remediation actions detailed in this alert will also remediate CVE-2026-58644 (CC-4816), allowing both cyber alerts to be marked as "complete" in the Respond to an NHS Cyber Alert (RtaNCA) portal. The remediation actions detailed in CC-4816 do not remediate CVE-2026-50522 (this alert).


Remediation advice

Affected organisations must review Microsoft's security advisory for CVE-2026-50522 and follow the remediation steps below.

Applying the "Remediation Steps" detailed below will remediate both CVE-2026-58644 (from CC-4816) and CVE-2026-50522 (this alert). Organisations must update SharePoint Server appliances to one of the versions detailed below or later.


Remediation steps

Type Step
Patch

Required: Patch to a fixed version

Organisations must update on-premises deployments of Microsoft SharePoint Server to the latest version available. Fixed releases include:

  • SharePoint Enterprise Server 2016: build 16.0.5561.1001 or later
  • SharePoint Server 2019: build 16.0.10417.20175 or later
  • SharePoint Server Subscription Edition: build 16.0.19725.20434 or later

Note: SharePoint Server 2016 and 2019 are no longer supported. Organisations should migrate to a supported version.


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
Action

Required: Rotate credentials on internet-facing SharePoint Servers

Observed exploitation of CVE-2026-50522 has involved attackers obtaining SharePoint machine keys via a single request. Organisations must rotate credentials on any internet-facing SharePoint Servers.

If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. 




Last edited: 22 July 2026 11:56 am