Microsoft has issued a security update addressing CVE-2026-50522, a critical remote code execution vulnerability in on-premises SharePoint Server. This vulnerability allows an authenticated site owner to execute arbitrary code and potentially steal machine keys for persistent access. Active exploitation has been reported following the release of proof-of-concept code. Organizations using SharePoint Server are urged to apply the security update immediately to mitigate risks.
What the Advisory Covers
This advisory details a significant vulnerability in Microsoft SharePoint Server that could lead to unauthorized code execution. The flaw is particularly concerning as it can be exploited by authenticated users, making it critical for organizations to address it promptly.
Affected Products and Versions
- Microsoft SharePoint Server (on-premises)
Severity and Exploitation Status
The vulnerability is classified as critical, with reports of active exploitation following the availability of proof-of-concept code. Organizations should prioritize remediation efforts to protect their systems.
Available Patches or Fixed Versions
Microsoft has released a security update to address CVE-2026-50522. Organizations are encouraged to apply this update as soon as possible to mitigate the risk associated with this vulnerability.
Recommended Actions
- Apply the security update for SharePoint Server immediately.
- Review user permissions to limit access to authenticated site owners where possible.
- Monitor for unusual activity that may indicate exploitation attempts.
For further details, refer to the Check Point Research advisory.


