A newly disclosed vulnerability, tracked as CVE-2026-50522, is rattling enterprise IT teams as it allows unauthenticated attackers to remotely execute code on on-premises Microsoft SharePoint servers. The flaw carries a critical CVSS score of 9.8 and stems from deserialization of untrusted data, a bug class that has repeatedly plagued SharePoint in 2026. CVE-2026-50522 affects on-premises x64 deployments of Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. An attacker can send a specially crafted serialized object to a vulnerable endpoint without prior authentication or user interaction, triggering arbitrary code execution in the SharePoint server’s...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!