
A critical Microsoft SharePoint Server vulnerability is now being actively exploited by attackers after a working proof-of-concept exploit was published online. Tracked as CVE-2026-50522, the flaw was patched in Microsoft’s July 2026 Patch Tuesday — but the public release of a working exploit has dramatically raised the risk for organizations that have not yet applied the update. The bug carries a CVSS score of 9.8 out of 10, the highest severity rating possible, and allows an unauthenticated attacker to remotely take full control of a SharePoint server without needing any credentials.
The attack works by sending a specially crafted network request that exploits how SharePoint handles certain serialized data. Once an attacker gains code execution on the server, they can read and modify all documents stored on it, harvest credentials, and use the server as a foothold to move deeper into an organization’s network. The vulnerability was originally demonstrated live at the Pwn2Own Berlin security contest, meaning attackers knew a working exploit existed even before the public PoC was released.
How to check if you’re affected
Affected versions include SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016 Enterprise. To check your version, open the SharePoint Central Administration site and go to Upgrade and Migration → Check product and patch installation status. If your server shows a build older than the July 2026 patch, you are vulnerable. Microsoft 365 and SharePoint Online are not affected — this vulnerability only applies to on-premises SharePoint Server installations.
