CISA KEV Alert 7/22/2026, 8:21:22 PM

CISA Adds CVE-2026-50522 to Known Exploited Vulnerabilities Catalogue

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

CISA has added CVE‑2026-50522 to its Known Exploited Vulnerabilities catalogue, affecting Microsoft SharePoint. The vulnerability is described as a deserialization of untrusted data flaw that could allow an unauthenticated attacker to execute code over a network.

The flaw is a network‑reachable deserialisation issue in SharePoint that permits remote code execution. It carries a CVSS v3.1 base score of 9.8, rating it as critical. Microsoft has released a patch that addresses the vulnerability, and the advisory is available via the MSRC update guide.

Because the entry appears in the KEV catalogue, active exploitation has been confirmed in the wild. No ransomware campaign has been publicly linked to this CVE at this time. CISA has set a remediation deadline of 26 July 2026 for federal agencies to apply the required mitigations.

CISA’s required action is: “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.” This directive binds Federal Civilian Executive Branch (FCEB) agencies; all other organisations should likewise review their SharePoint exposure and apply the vendor’s patch or mitigations without delay.

For full details, consult the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-50522 and the CISA KEV catalogue.

View CISA KEV Entry

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline