Hackers Exploit Critical SharePoint Flaw to Steal Machine Keys


sharepoint exploit
Image credit: Microsoft

CVE-2026-50522 is under active exploitation, allowing attackers to execute code remotely on vulnerable on-premises Microsoft SharePoint servers without authentication.

CISA recently flagged three actively exploited SharePoint vulnerabilities, but researchers have now also observed attacks targeting CVE-2026-50522.

Microsoft fixed the critical vulnerability in its July 2026 security updates.

Attackers Steal SharePoint Machine Keys

Hackers exploiting CVE-2026-50522 are stealing machine keys from compromised SharePoint servers.

SharePoint uses these keys to generate and validate authentication tokens. Attackers who obtain them can create valid tokens, impersonate legitimate users, and access SharePoint sites and stored documents.

Patching the vulnerable server may not remove this access. Stolen machine keys can continue validating forged authentication tokens after administrators install the security update.

Exploitation Began After Public PoC Release

Security researchers at watchTowr observed exploitation attempts shortly after a working proof-of-concept exploit became publicly available.

The company’s honeypot network recorded successful SharePoint compromises using the disclosed exploitation technique.

Defused also detected related SharePoint deserialization attacks as early as July 17.

PowerShell Exploit Is Publicly Available

A PowerShell proof-of-concept exploit for CVE-2026-50522 is now publicly available.

The exploit targets a SharePoint deserialization path to execute arbitrary code on the affected server. It sends a crafted authentication token containing a malicious .NET payload to a SharePoint sign-in endpoint.

Because the vulnerability requires no authentication, attackers can target exposed SharePoint servers remotely over the network.

Administrators Must Patch and Rotate Keys

Organizations running on-premises SharePoint should install the latest security updates immediately.

However, patching only closes the vulnerability. It does not remove authentication tokens, machine keys, or other access mechanisms that attackers may have obtained before the update.

Administrators with potentially exposed servers should rotate relevant machine keys and credentials. They should also investigate affected systems for unauthorized access, malicious payloads, and other signs of persistence.

In other security news, Hugging Face was recently breached, and OpenAI confirmed that one of its models was responsible after escaping a sandboxed testing environment.

Via BleepingComputer

More about the topics: microsoft, Sharepoint

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages