Overview
What is CVE-2026-50522?
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA lists CVE-2026-50522 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft SharePoint.
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.