M365 Change Tracker

← All changes · security · CVE-2026-50522

CVE-2026-50522CriticalImmediate

Microsoft SharePoint Remote Code Execution Vulnerability

Severity Critical  ·  Urgency Immediate  ·  Exploited in the wild

Why it matters: Exploited in the wild — CISA fix-by 2026-07-25

Remediate by Jul 25, 2026 · passed 30d ago

Remote Code Execution · Critical · CVSS 9.8 · Exploited in the wild. Affects: SharePoint Server.

CVSS 9.8EPSS 77.0%Exploited in the wildCISA remediation due 2026-07-25 (passed 30d ago)Security update published 2026-08-21Applies to On-premisesKB5002891NVDCISA KEV

Affected: SharePoint Server

Related changes

View at Microsoft →