Priority: CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities Catalog on July 22, 2026. Treat this as urgent maintenance for self-managed Microsoft SharePoint Server: assign an owner, follow Microsoft's update guidance, protect recovery readiness, and verify approved collaboration services after the maintenance window.
This is a defensive update guide. It intentionally omits attack methods, testing details, and technical material that could be misused against another organization.
Who needs to review this now
- Organizations that operate Microsoft SharePoint Server themselves, including collaboration farms managed by an internal IT team or a service provider.
- Teams using SharePoint Server Subscription Edition, or another SharePoint Server release that Microsoft identifies in its Security Update Guide as affected.
- Hosting and managed-service teams that own the Windows, database, identity, backup, or network layers supporting a SharePoint farm.
Start with a current asset and ownership list. Identify each SharePoint farm, its support status, the business owner, the approved maintenance contact, and the recovery path. If a server is internet-facing or its exposure is uncertain, give it the earliest approved change window.
Patch and recovery checklist
- Review the Microsoft Security Update Guide for CVE-2026-50522 and match its guidance to the installed SharePoint Server release.
- Use the current Microsoft-serviced update path for that release. For SharePoint Server Subscription Edition, Microsoft lists the July 2026 security update in its official update documentation.
- Confirm that recovery materials, change approval, service owners, and normal business contacts are ready before work begins. This guide does not require creating a new backup to read or publish it.
- Apply the vendor-supported maintenance process during the approved window and record the resulting update state.
- Verify normal sign-in, approved document access, search, workflows, integrations, monitoring, and backup jobs after the change.
- Review administrator changes and service alerts around the exposure period. Escalate unexplained activity through the organization's incident-response process rather than deleting evidence.
Support status matters
Do not treat an unsupported SharePoint Server deployment as patched simply because another farm completed maintenance. Confirm the support lifecycle and available Microsoft remediation for each release. If a supported update path is not available, reduce exposure, involve the service owner, and plan a supported migration or replacement with Microsoft guidance.
After the maintenance window
Record the patch result, the farm owner, validation outcome, and any remaining follow-up. Share a concise status with teams that depend on the platform so they know what changed, what was verified, and when normal maintenance is complete.
Related Fix I.T. Phill guidance
- Fix I.T. Phill security updates and maintenance checklists
- Earlier Microsoft SharePoint CISA KEV update checklist
- Microsoft SharePoint Server CVE-2026-56164 checklist


