A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a bug class that has repeatedly plagued SharePoint in 2026. CVE-2026-50522 affects on-premises x64 deployments of Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. An attacker can send a specially crafted serialized object to a vulnerable endpoint without prior authentication or user interaction, triggering arbitrary code execution in the SharePoint server’s...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!