CVE-2026-50522: Microsoft SharePoint's Next Deserialization RCE, Exploited Days After a Public PoC

Technical root cause of the SharePoint deserialization RCE exploited within days of public proof-of-concept release.

CVE-2026-50522: Microsoft SharePoint's Next Deserialization RCE, Exploited Days After a Public PoC
Photo by Tony Marinescu / Unsplash
📌
Security Roundup Series: Week of July 20, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-50522 (CWE-502) Severity: CVSS 9.8 Status: ⚠️ Actively Exploited In-The-Wild Target Component: Microsoft SharePoint Server

What's Affected

All supported on-premises Microsoft SharePoint Server editions: Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. SharePoint Online / Microsoft 365 is not affected, since this is an on-prem server-side deserialization bug tied to the product's WS-Federation sign-in handling.

The Vulnerability

CVE-2026-50522, CVSS 9.8: a deserialization of untrusted data flaw in SharePoint Server that allows an unauthenticated attacker to achieve remote code execution over the network. It is the latest in a recurring family of SharePoint deserialization bugs that trace back to how the server processes forged authentication tokens.

Attack Chain Breakdown

A public PowerShell proof-of-concept, released by researcher Janggggg, triggers the flaw as follows: the attacker crafts a malicious .NET BinaryFormatter payload and embeds it as the cookie of a forged SecurityContextToken. That token is wrapped inside a WS-Federation sign-in response and POSTed to SharePoint's /_trust/default.aspx endpoint. When SharePoint's vulnerable deserialization path processes the incoming token, the embedded payload executes as arbitrary code in the context of the SharePoint application pool. From there, watchTowr and other researchers report attackers moving quickly to exfiltrate IIS machine keys, which can be used to forge valid __VIEWSTATE payloads and maintain persistence even after the underlying RCE is patched.

Indicators to Check For

Unexpected POST requests to /_trust/default.aspx from unfamiliar source IPs; IIS worker process (w3wp.exe) spawning unusual child processes such as cmd.exe or powershell.exe; unexplained access to or modification of machine key configuration; and any outbound connections from the SharePoint server that don't match normal application behavior.

Remediation

Patch immediately, this CVE is in CISA's KEV catalog with a federal remediation deadline of July 25. Because attackers are targeting IIS machine keys specifically, patching alone is not sufficient if a machine key was already stolen: rotate ASP.NET machine keys on affected servers after patching, and if you can't confirm the server was clean before patching, treat it as compromised and consider rebuilding from a known-good state. Restrict access to /_trust/ endpoints where feasible, and review IIS and Windows Security event logs back to when the PoC became public.

This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther