CVE-2026-50522: Microsoft SharePoint's Next Deserialization RCE, Exploited Days After a Public PoC
Technical root cause of the SharePoint deserialization RCE exploited within days of public proof-of-concept release.
CVE-2026-50522 (CWE-502)
Severity: CVSS 9.8
Status: ⚠️ Actively Exploited In-The-Wild
Target Component: Microsoft SharePoint Server
What's Affected
All supported on-premises Microsoft SharePoint Server editions: Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. SharePoint Online / Microsoft 365 is not affected, since this is an on-prem server-side deserialization bug tied to the product's WS-Federation sign-in handling.
The Vulnerability
CVE-2026-50522, CVSS 9.8: a deserialization of untrusted data flaw in SharePoint Server that allows an unauthenticated attacker to achieve remote code execution over the network. It is the latest in a recurring family of SharePoint deserialization bugs that trace back to how the server processes forged authentication tokens.
Attack Chain Breakdown
A public PowerShell proof-of-concept, released by researcher Janggggg, triggers the flaw as follows: the attacker crafts a malicious .NET BinaryFormatter payload and embeds it as the cookie of a forged SecurityContextToken. That token is wrapped inside a WS-Federation sign-in response and POSTed to SharePoint's /_trust/default.aspx endpoint. When SharePoint's vulnerable deserialization path processes the incoming token, the embedded payload executes as arbitrary code in the context of the SharePoint application pool. From there, watchTowr and other researchers report attackers moving quickly to exfiltrate IIS machine keys, which can be used to forge valid __VIEWSTATE payloads and maintain persistence even after the underlying RCE is patched.
Indicators to Check For
Unexpected POST requests to /_trust/default.aspx from unfamiliar source IPs; IIS worker process (w3wp.exe) spawning unusual child processes such as cmd.exe or powershell.exe; unexplained access to or modification of machine key configuration; and any outbound connections from the SharePoint server that don't match normal application behavior.
Remediation
Patch immediately, this CVE is in CISA's KEV catalog with a federal remediation deadline of July 25. Because attackers are targeting IIS machine keys specifically, patching alone is not sufficient if a machine key was already stolen: rotate ASP.NET machine keys on affected servers after patching, and if you can't confirm the server was clean before patching, treat it as compromised and consider rebuilding from a known-good state. Restrict access to /_trust/ endpoints where feasible, and review IIS and Windows Security event logs back to when the PoC became public.
Related
This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.