Security Advisory 2026-009

Release Date:

Critical Vulnerability in Microsoft SharePoint

Download

History:

  • 22/07/2026 --- v1.0 -- Initial publication

Summary

On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code, and later, successful exploitation attempts [2].

CERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet.

Technical Details

The vulnerability CVE-2026-50522, with a CVSS score of 9.8, is a critical deserialisation vulnerability in Microsoft SharePoint. It allows a remote attacker to execute code on the affected assets.

While Microsoft suggests this vulnerability requires some level of authentication [1], recent findings may indicate otherwise [2, 3].

Affected Products

This vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 [1].

Recommendations

CERT-EU strongly recommends to update affected servers as soon as possible, and to run compromise assessment to identify potentially affected SharePoint instances.

CERT-EU also recommends to rotate credentials on any assets that may have been vulnerable and exposed on the internet.

Considering the number of recent critical RCE vulnerability affecting SharePoint, exposing any SharePoint server on the internet should be reconsidered.

References

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522

[2] https://www.linkedin.com/posts/watchtowr_exploitation-alert-watchtowr-is-observing-activity-7485278595850940416-LSP8/

[3] https://x.com/DefusedCyber/status/2079128402855116858

We got cookies

We only use cookies that are necessary for the technical functioning of our website. Find out more on here.