SharePoint Remote Code Execution Vulnerabilities Enable Server-Side Code Execution
Executive Summary A ThreatLocker report published on 21 July 2026 detailed two critical deserialization vulnerabilities, CVE-2026-50522 and CVE-2026-58644, affecting on-premises Microsoft SharePoint Server deployments. The flaws can allow an authenticated attacker to submit malicious serialized data that is processed by vulnerable SharePoint components, resulting in remote code execution within the SharePoint server context. Successful exploitation could enable command execution, malware…
Read More