Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-50522 — Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | Kitploit
Tools/GitHubGitHub/chpratik/cve-2026-50522
Vulnerability AnalysisThreat IntelligencePapers & ResearchLearning & EducationIncident ResponseCurated Resources
GitHubchpratik/cve-2026-50522

CVE-2026-50522

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

View Repository
132 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2026-50522 — Microsoft SharePoint RCE Investigation

Critical SharePoint Deserialization Vulnerability Under Active Exploitation

CVE Severity CVSS CWE KEV EPSS

Created by Pratik Chhetri
Report Date: 2026-07-27


📌 Executive Snapshot

FieldFinding
VulnerabilityCVE-2026-50522
ProductMicrosoft SharePoint Server on-premises
Affected versionsSharePoint Server 2016, SharePoint Server 2019, SharePoint Server Subscription Edition before fixed builds
WeaknessCWE-502 — Deserialization of Untrusted Data
ImpactRemote Code Execution
CVSS v3.19.8 Critical — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.571010 / 98.974 percentile as of 2026-07-27
CISA KEVAdded 2026-07-22; due 2026-07-25
Ransomware usageUnknown per CISA KEV
Public PoCReported available; GitHub repositories observed
Active exploitationConfirmed by CISA KEV and public-sector/security reporting
Primary riskRCE plus SharePoint/IIS machine-key theft enabling token forgery and persistence

🚨 Key Takeaways

CVE-2026-50522 is not a routine patching item. It is a Critical RCE with public exploit reporting, KEV status, and observed machine-key theft.

  • Attackers have reportedly abused the flaw to obtain SharePoint machine keys.
  • Stolen machine keys can allow forged authentication tokens and access that may survive patching.
  • Patching closes the vulnerability, but exposed servers still require hunting and key rotation.
  • Internet-facing on-premises SharePoint servers should be handled as emergency risk.

🧭 Attack Path

flowchart TD
    A[Remote attacker] --> B[Reachable on-prem SharePoint]
    B --> C[Crafted request to sign-in/auth surface]
    C --> D[Unsafe deserialization]
    D --> E[Remote code execution]
    E --> F[Machine-key theft]
    F --> G[Forge auth tokens/cookies]
    G --> H[Impersonate users]
    H --> I[Access SharePoint sites and documents]
    F --> J[Persistence after patch if keys not rotated]

🧩 Affected Versions and Fixes

ProductVulnerable beforeRequired fixed buildPatch
SharePoint Server 2016 / Enterprise Server 201616.0.5561.100116.0.5561.1001 or laterKB5002891
SharePoint Server 201916.0.10417.2017516.0.10417.20175 or laterKB5002883
SharePoint Server Subscription Edition16.0.19725.2043416.0.19725.20434 or laterKB5002882

🧠 Root Cause Summary

ZDI identifies the affected area as the SessionSecurityTokenHandler class. The flaw is caused by insufficient validation of user-supplied data, enabling unsafe deserialization and remote code execution in affected SharePoint installations.

Public reporting describes a PoC path involving SharePoint sign-in processing and /_trust/default.aspx. Exact implementation details are limited because SharePoint source and patch diff are not public.


🔥 Threat Intelligence Summary

ItemStatusConfidence
Active exploitationConfirmed by CISA KEVHigh
Public PoCReported; GitHub repositories foundMedium
Exploit-DB entryNot FoundMedium-High
Metasploit moduleNot FoundMedium
Named threat actorNot FoundMedium
Ransomware campaignUnknown per CISAHigh
Machine-key theftReported by multiple sourcesHigh

🕒 Investigation Timeline

timeline
    title CVE-2026-50522 Timeline
    2026-05-21 : Reported to vendor via ZDI/Pwn2Own path
    2026-07-14 : Microsoft advisory and patches released
    2026-07-15 : ZDI advisory published
    2026-07-17 : Exposure advisory and early exploitation reporting window
    2026-07-20 : Public PoC reportedly appears; exploitation observed within hours
    2026-07-22 : CISA adds CVE-2026-50522 to KEV
    2026-07-25 : CISA remediation due date
    2026-07-27 : Report finalized

🛠️ Defender Action Plan

Immediate — First 24 Hours

  • Inventory all on-premises SharePoint servers.
  • Prioritize internet-facing and partner-accessible farms.
  • Apply Microsoft July 2026 SharePoint updates.
  • Verify fixed builds across every farm member.
  • Preserve IIS, ULS, WAF, Defender, Windows, and EDR logs.
  • Hunt for suspicious POST /_trust/default.aspx activity.
  • Hunt for w3wp.exe spawning command-line tools.
  • Hunt for new/modified .aspx, .ashx, .asmx, .dll, and web.config files.
  • Review Microsoft Defender/AMSI detections.
  • Rotate machine keys after cleanup.

Hardening — Next 7 Days

  • Enable/verify AMSI integration for every SharePoint web application.
  • Use Request Body Scan Full Mode where feasible.
  • Remove direct internet exposure.
  • Place SharePoint behind authenticated Layer 7 reverse proxy/WAF.
  • Block external Central Administration access.
  • Restrict farm/database communications.
  • Review service accounts, farm admins, timer jobs, scheduled tasks, and farm solutions.
  • Plan migration away from unsupported SharePoint 2016/2019 where applicable.

🔎 High-Value Detection Ideas

Web / IIS / WAF

POST /_trust/default.aspx
AND request contains any of:
  SecurityContextToken
  BinaryFormatter
  AAEAAAD

Endpoint / EDR

Parent process: w3wp.exe
Child process: cmd.exe, powershell.exe, pwsh.exe, certutil.exe, bitsadmin.exe,
               mshta.exe, rundll32.exe, regsvr32.exe, cscript.exe, wscript.exe

File Integrity

Monitor:
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\16\TEMPLATE\LAYOUTS\
C:\inetpub\wwwroot\wss\VirtualDirectories\

Alert on new or modified:
*.aspx, *.ashx, *.asmx, *.dll, web.config

Microsoft Defender / AMSI Detections From CISA Guidance

Exploit:Script/SuspSignoutReqBody.A
Exploit:Script/ToolPaneAuthBypass.A
Exploit:Script/ToolPaneAuthBypass.C
Backdoor:MSIL/LeakFang.A!dha

📊 Risk Matrix

ExposureLikelihoodImpactPriority
Internet-facing vulnerable SharePointHighCriticalP0
Partner/VPN-accessible vulnerable SharePointHighCriticalP0/P1
Internal-only vulnerable SharePoint with broad accessMedium-HighHighP1
Patched but exposed before remediationMediumHighP1 — hunt and rotate
Patched, hunted, keys rotated, hardenedLow-MediumMediumMonitor

✅ Verified Indicators and Gaps

CategoryResult
Attacker IPsNot Found
Attacker domainsNot Found
Full malicious URLsNot Found
Malicious file hashesNot Found
Registry keysNot Found
MutexesNot Found
Verified network path/_trust/default.aspx
Verified detection namesMicrosoft Defender/AMSI names listed above
Verified sensitive targetSharePoint/IIS machine keys

📚 Full Report

The detailed analyst report is available in this repository:

➡️ CVE-2026-50522_CTI_Report.md

It includes:

Download Tool