CVE-2026-50522 · Critical · CISA KEV
Microsoft SharePoint Deserialization Vulnerability Actively Exploited (KEV)
Threat Engine Auto-Feed · data current as of 2026-07-24
A critical deserialization of untrusted data vulnerability in Microsoft SharePoint (CVE-2026-50522) allows unauthorized attackers to execute code remotely. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has a very high EPSS percentile, indicating significant exploitation probability.
- CVSS:
- EPSS percentile: 0.9897
- Exploitation pressure: 84/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 99th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
Deserialization of untrusted data occurs when an application converts data from an external source back into an object without proper validation. If an attacker can control this external data, they can inject malicious code that the application will then execute when it attempts to deserialize the data.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using Microsoft SharePoint, particularly those in Financial Services and Technology sectors, are at heightened risk due to documented targeting by sophisticated threat actors.
- Enterprises with critical data or services hosted on SharePoint are especially vulnerable.
Misconfigurations that escalate it
- Any SharePoint instance that processes untrusted or unvalidated external data is susceptible.
- Lack of robust input validation and secure deserialization practices within custom SharePoint applications or integrations.
High-impact scenarios
- Unauthorized remote code execution on SharePoint servers, leading to full system compromise.
- Data exfiltration, modification, or destruction from compromised SharePoint environments.
- Establishment of persistent access within the network, enabling further lateral movement and broader impact.
- Disruption of critical business operations reliant on SharePoint services.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor SharePoint server logs for unusual process execution, network connections, or file modifications.
- Implement intrusion detection systems (IDS) to identify anomalous traffic patterns to and from SharePoint servers.
- Regularly scan SharePoint environments for known vulnerabilities and misconfigurations.
Contain
- Isolate affected SharePoint servers from the network to prevent further compromise.
- Block suspicious IP addresses communicating with SharePoint instances.
- Review and restrict network access controls to SharePoint servers.
Patch
- Apply all available security updates and patches for Microsoft SharePoint immediately, prioritizing those addressing CVE-2026-50522.
- Ensure all SharePoint components and associated services are running the latest secure versions.
Frontier verdict — Critical
This is a critical, actively exploited vulnerability in Microsoft SharePoint with high exploitation probability (EPSS 99th percentile) requiring immediate patching and defensive measures.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.