{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-50522",
  "revision": 1,
  "title": "Microsoft SharePoint — deserialization RCE (CVE-2026-50522)",
  "summary": "Microsoft SharePoint unpacks untrusted data without checking it, letting an unauthenticated attacker with network access run code on the server. The Cybersecurity and Infrastructure Security Agency (CISA) lists it as exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.854,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-07-22",
    "prerequisites": "Network access to the SharePoint server; no authentication or user interaction required."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Microsoft's SharePoint update now; restrict internet exposure of SharePoint servers until patched and hunt for signs of compromise.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-50522",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50522",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522"
    }
  ],
  "published_at": "2026-07-14T17:17:01.547Z",
  "issued_at": "2026-09-22T06:10:25.213Z",
  "tags": [
    "microsoft",
    "sharepoint",
    "deserialization",
    "rce",
    "kev"
  ]
}
