Critical 9.1
KEV-listed
CVE-2026-50522
CISA warns of active exploitation of SharePoint zero-day vulnerabilities
Vendor / product: Microsoft SharePoint Server
Event date: 2026-07-22
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
CISA KEV catalog
Added to KEV
Federal remediation due
2026-07-25 (57 days overdue)
Ransomware campaign use
Unknown
CISA description
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Sources & citations (6)
- SharePoint zero-day grants Farm Admin rights, CISA warns notebookcheck.net · 2026-07-31
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks bleepingcomputer.com · 2026-08-11
- Эксперты R-Vision назвали трендовые уязвимости июля companies.rbc.ru · 2026-08-04
- Эксперты R-Vision назвали наиболее опасные уязвимости июля для корпоративной инфраструктуры cnews.ru · 2026-08-05
- В фокусе RVD: дайджест трендовых уязвимостей июля habr.com · 2026-08-04
- August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? helpnetsecurity.com · 2026-08-07
References
See CVE-2026-50522 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →