CRITICAL
CVE-2026-50522
CVSS
9.8
KEV
Description
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Summary dbcve.org
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthenticated remote attacker to execute arbitrary code over the network due to unsafe deserialization of input data processed by the SharePoint application.
Mitigation
Apply Microsoft security updates for SharePoint immediately; in the interim, restrict network access to SharePoint servers and implement WAF rules to detect deserialization attack patterns.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
85.4%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.