PT-2026-58208 · Microsoft · Sharepoint Server

CVE-2026-50522

·

Published

2026-05-21

·

Updated

2026-09-03

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Server Subscription Edition (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified)
Description An unauthenticated remote code execution flaw exists due to the unsafe deserialization of untrusted data within the SessionSecurityTokenHandler class. An attacker can exploit this by sending a crafted request containing a malicious .NET BinaryFormatter payload via a fake SecurityContextToken cookie to the trust/default.aspx endpoint. This allows the execution of arbitrary code on the server, potentially leading to full environment compromise, data theft, and lateral movement. Real-world incidents have been observed where threat actors exploit this flaw to steal SharePoint machine keys, which are used for cryptographic operations. Stealing these keys allows attackers to forge authentication tokens and maintain persistent access to the system even after the vulnerability has been patched.
Recommendations Apply the security updates released in the July PatchTuesday for all affected SharePoint servers. Rotate machine keys on all potentially compromised servers to prevent persistent access. Conduct a thorough forensic analysis to identify signs of machine key exfiltration or unauthorized activity.

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10084
CVE-2026-50522
ZDI-26-412
ZDI-26-413

Affected Products

Sharepoint Server