Critical SharePoint RCE Vulnerability CVE-2026-50522 Under Active Exploitation

A critical vulnerability identified as CVE-2026-50522 has been discovered in Microsoft SharePoint Server, posing significant security risks. This flaw, rated with a CVSS score of 9.8, allows unauthorized remote code execution through the deserialization of untrusted data. The affected versions include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.

Microsoft has acknowledged that an attacker, authenticated as at least a Site Owner, could exploit this vulnerability to inject and execute arbitrary code remotely on the SharePoint Server. The company has assessed the exploitability of this vulnerability as “Exploitation More Likely,” indicating a high probability of active exploitation.

Security researchers have observed active exploitation of CVE-2026-50522 in the wild. Attackers are reportedly leveraging this vulnerability to steal machine keys, thereby maintaining persistent access to compromised systems. This method involves sending a single request to extract SharePoint machine keys, which can then be used to sustain unauthorized access.

In response to these developments, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about the exploitation of multiple SharePoint Server vulnerabilities, including CVE-2026-50522. These vulnerabilities are being used by threat actors to gain unauthorized access to on-premises SharePoint instances, execute remote code, and perform post-exploitation activities such as stealing Internet Information Services (IIS) machine keys and deploying malware.

Given the severity and active exploitation of CVE-2026-50522, it is imperative for organizations using affected versions of SharePoint Server to apply the necessary patches promptly. Additionally, rotating credentials on any potentially exposed assets is crucial to mitigate the risk of persistent unauthorized access. This situation underscores the importance of timely vulnerability management and proactive security measures to protect critical infrastructure from emerging threats.