--- licence_title: Creative Commons Attribution 4.0 International (CC-BY 4.0) licence_link: https://creativecommons.org/licenses/by/4.0/ licence_restrictions: https://cert.europa.eu/legal-notice licence_author: The Cybersecurity Service for the Union institutions, bodies, offices and agencies title: 'Critical Vulnerability in Microsoft SharePoint' number: '2026-009' version: '1.0' original_date: '2026-07-14' date: '2026-07-22' --- _History:_ * _22/07/2026 --- v1.0 -- Initial publication_ # Summary On 14 July 2026, Microsoft released a security update addressing a critical Remote Code Execution (RCE) in Microsoft SharePoint Server [1]. On 20 July 2026, WatchTowr identified a **proof-of-concept exploit code**, and later, **successful exploitation attempts** [2]. CERT-EU strongly recommend to update affected servers and to rotate credentials on any assets that may have been vulnerable and exposed on the internet. # Technical Details The vulnerability **CVE-2026-50522**, with a CVSS score of 9.8, is a critical deserialisation vulnerability in Microsoft SharePoint. It allows a remote attacker to execute code on the affected assets. While Microsoft suggests this vulnerability requires some level of authentication [1], recent findings may indicate otherwise [2, 3]. # Affected Products This vulnerability affects Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 [1]. # Recommendations CERT-EU strongly recommends to update affected servers as soon as possible, and to run compromise assessment to identify potentially affected SharePoint instances. CERT-EU also recommends to rotate credentials on any assets that may have been vulnerable and exposed on the internet. Considering the number of recent critical RCE vulnerability affecting SharePoint, exposing any SharePoint server on the internet should be reconsidered. # References [1] [2] [3]