Knox CVE Database
/
CVE-2026-50522
Critical
9.8

CVE-2026-50522: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Added to the CISA KEV catalog:
July 22, 2026

Overview

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Vulnerability details

Affected vendor
Microsoft
Affected product
SharePoint
Weakness type (CWE)
CWE-502

Microsoft SharePoint contains a deserialization of untrusted data flaw (CWE-502) in which the server accepts and processes attacker-supplied serialized data without adequate validation. In .NET-based server applications such as SharePoint, deserialization routines can be abused to instantiate arbitrary object graphs, triggering code execution as a side effect of the deserialization process itself. Because the flaw exists in a network-facing component, no authentication or user interaction is required for the payload to reach the vulnerable code path.


An attacker with network access to an unpatched SharePoint server sends a crafted serialized payload to a reachable endpoint. SharePoint deserializes the payload, executing attacker-controlled code in the context of the SharePoint service process. The result is full confidentiality, integrity, and availability impact on the server. No credentials are needed and no user action is required, making this exploitable by any party that can reach the server over the network. Affected versions are SharePoint Enterprise Server 2016 below 16.0.5561.1001, SharePoint Server 2019 below 16.0.10417.20175, and SharePoint Server Subscription Edition below 16.0.19725.20434.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor IIS and SharePoint Unified Logging Service (ULS) logs for HTTP requests to SharePoint endpoints that return unexpected 500-series errors or abnormal response sizes from unauthenticated sessions, which may indicate malformed deserialization payloads being processed.
  • Alert on unexpected child processes spawned by the SharePoint application pool worker process (w3wp.exe), such as cmd.exe, powershell.exe, or wscript.exe, which are not part of normal SharePoint operation and indicate post-deserialization code execution.
  • Review Windows Security event logs for new service installations, scheduled task creation, or privilege changes originating from the SharePoint service account identity following any anomalous w3wp.exe activity.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 25, 2026

Additional hardening

  • Upgrade SharePoint Enterprise Server 2016 to 16.0.5561.1001 or later, SharePoint Server 2019 to 16.0.10417.20175 or later, and SharePoint Server Subscription Edition to 16.0.19725.20434 or later. See References for the vendor advisory.
  • Restrict network access to SharePoint servers using perimeter controls or host-based firewall rules so that only authorized clients and IP ranges can reach SharePoint HTTP/HTTPS endpoints, reducing the pool of potential attackers.
  • Apply the principle of least privilege to the SharePoint service account: remove local administrator rights and restrict its ability to spawn child processes or write outside designated SharePoint directories.
  • Conduct forensic triage per CISA BOD 26-04 guidance (see References) on any SharePoint server that was internet-exposed while running an affected version, focusing on w3wp.exe process history and new scheduled tasks or services.

Key dates

Published (NVD)
July 14, 2026
Added to CISA KEV
July 22, 2026
Remediation deadline
July 25, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-50522 affect my FedRAMP authorization?

If Microsoft SharePoint runs inside your authorization boundary, yes. CVE-2026-50522 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of July 25, 2026. For a FedRAMP-authorized service, an unpatched KEV within the boundary is a finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a deficiency.

How does Knox help me handle CVE-2026-50522?

Knox does not patch your software. Remediating Microsoft SharePoint is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The patch is yours to apply; maintaining a compliant posture while you apply it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-50522. Exposure surfaces during ongoing monitoring rather than waiting until an assessor flags it at review time, giving your team the lead time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-50522 isn't remediated by July 25, 2026?

If CVE-2026-50522 is not remediated by July 25, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult agency conversation. Meeting the deadline keeps your authorization clean and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting