Cyber Resilience
← All news

New critical CVE: CVE-2026-50522 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a

Our takeAnother SharePoint deserialization RCE, critical severity. Not one of the three CVEs CISA says are under active exploitation (32201, 45659, 56164) — patch it anyway, on-prem SharePoint is now averaging multiple deserialization bugs per advisory cycle.
Sources (12)
What this means for you — Security leader:Patch all on-prem SharePoint (Subscription Edition, 2019, 2016) against CVE-2026-56164 and related deserialization/auth flaws now; confirm which of your instances are internet-facing and check CISA's KEV catalog for the actively-exploited set (32201, 45659, 56164).
What this means for you — Lean IT orgs:If you run SharePoint on your own server (not Microsoft 365 cloud), get your IT provider to patch it immediately — attackers are actively breaking into unpatched on-prem SharePoint servers right now.
What this means for you — MSP:Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.
What this means for you — Researcher:Multiple SharePoint deserialization/auth CVEs landed together (50522, 58644, 55040, 56164) alongside CISA's advisory naming a different exploited set (32201, 45659, 56164) — worth mapping overlap and checking if 50522/58644 share a root cause with the confirmed-exploited chain.