01 / EXECUTIVE SUMMARY
What the evidence
establishes.
CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities Catalog. The SharePoint deserialization flaw can allow an unauthorized attacker to execute code over a network.
01 / EXECUTIVE SUMMARY
CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities Catalog. The SharePoint deserialization flaw can allow an unauthorized attacker to execute code over a network.
02 / WHAT HAPPENED
CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities Catalog. The SharePoint deserialization flaw can allow an unauthorized attacker to execute code over a network.
The chain distinguishes what appeared valid, what was physically true, which authority followed and what consequence the source documents.
Network-delivered content was processed inside an enterprise collaboration boundary.
Untrusted serialized data could cross that boundary and exercise code-execution authority without an authorized principal.
CISA directed agencies to apply vendor mitigations under BOD 26-04 or discontinue use when mitigations are unavailable.
CISA classified the vulnerability as known exploited; no attributable public loss total is stated in the catalog.
A verified execution boundary that rejects untrusted data before it can acquire process authority inside enterprise infrastructure.
ECR separates a documented monetary floor from a modeled social and economic consequence envelope. It is not an accounting loss figure.
The public record establishes the control failure or authority action, not a realized loss total. The range is a deliberately wide scenario envelope.
Exploit status, product and required action come from the official CISA KEV record. 4SI supplies the Presence interpretation and score.
Data accepted by a trusted system can become consequential authority even when no accountable principal authorized execution.
4SI does not claim to have independently verified the underlying event. Scores, boundary analysis and economic ranges interpret published evidence; they are not probabilities, compliance findings, valuations or loss forecasts.
Related cases are editorially connected by domain, authority pattern or missing physical trust boundary.