Skip to main content

Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522

Advisory

Advisory
23 July 2026

 

Background

 

CVSSv3 Score: Base 9.8 Critical

A critical security vulnerability (CVSS 3.1 score: 9.8) has been identified in on-premises deployments of Microsoft SharePoint Server. This vulnerability allows unauthenticated users to run malicious code on SharePoint servers to steal IIS machine keys which can be used to bypass all login screens and masquerade as administrators. This flaw is caused by the deserialization of untrusted data within SharePoint's core processing components, allowing a remote, unauthenticated attacker to execute malicious code on vulnerable systems.

Threat actors are actively exploiting this vulnerability to steal IIS machine keys, granting them the ability to bypass all login screens, forge administrative access, and maintain long-term persistence. Because stolen machine keys may allow attackers to retain access even after a system is patched, remediation requires immediate installation of Microsoft’s July 2026 updates and a manual rotation of the servers’ IIS machine key.

 

Impact

  • Allows unauthorized attackers to execute code over a network
  • Enables the deployment web shells for persistent access
  • Allows access to or modification of sensitive SharePoint documents
  • Enables the theft of credentials or authentication-related
  • Move laterally within the organisation’s network
  • May disrupt SharePoint services

 

Affected Products

 

                                                                                                                                                        
ProductAffected Versions
Microsoft Sharepoint Server Subscription EditionVersions prior to 16.0.19725.20434
Microsoft Sharepoint Server 2019Versions prior to 16.0.10417.20175
Microsoft Sharepoint Server 2016Versions prior to 16.0.5561.1001

 

Recommendations

 

  • Apply the latest security updates provided by Microsoft to affected SharePoint Server systems as soon as possible.
  • Identify and patch all affected SharePoint servers within the organization’s environment.
  • Conduct threat hunting and a compromise assessment to identify possible signs of exploitation.
  • Manually Rotate the IIS Machine Keys
  • Rotate credentials and sensitive secrets if there is any indication that the affected SharePoint server may have been compromised.
  • Restrict external access to on-premises SharePoint servers by allowing access only from trusted networks or through secure remote access solutions.
  • Monitor SharePoint and system logs for suspicious activity, including unusual login attempts, abnormal requests, or unauthorized changes.
  • Review and strengthen access controls by enforcing the principle of least privilege and removing unnecessary administrative access.
  • Maintain regular backups of critical SharePoint data and verify that recovery procedures are available.

 

References