CRITICAL

CVE-2026-50522

Microsoft Sharepoint Server 2026-07-14 CVSS v3.1
CVSS
9.8
KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Summary dbcve.org

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthenticated remote attacker to execute arbitrary code over the network due to unsafe deserialization of input data processed by the SharePoint application.

Mitigation

Apply Microsoft security updates for SharePoint immediately; in the interim, restrict network access to SharePoint servers and implement WAF rules to detect deserialization attack patterns.

Patch Commit

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

85.4%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE