A critical deserialization RCE vulnerability (CVE-2026-50522, CVSS 9.8) in Microsoft SharePoint Server has a public proof-of-concept and confirmed exploitation in the wild. The flaw affects SharePoint Server Subscription Edition, 2019, and Enterprise Server 2016. Defenders should treat internet-exposed SharePoint instances as potentially compromised, patch immediately, and rotate credentials.
CVE-2026-50522
1 post
Security Advisory 2026-009