Skip to content

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability - 20260722001

Overview

The WASOC has been made aware of a critical remote code execution vulnerability affecting Microsoft SharePoint Server. Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

What is vulnerable?

Product(s) Affected Version(s) CVE CVSS Severity
Microsoft SharePoint Server All versions prior to 16.0.19725.20434 CVE-2026-50522 9.8 Critical

What has been observed?

The WASOC has observed one or more of the mentioned items have been added to the CISA Known Exploited Vulnerability catalaog. The WASOC has not received any reports of exploitation of this vulnerability on Western Australian Government networks at the time of writing.

Recommendation

The WASOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframes (refer Patch Management):

Change Log

  • 2026-07-22: Initial publication.
  • 2026-07-23: Added to CISA KEV catalog.