Hackers Exploit Critical SharePoint Flaw to Steal Machine Keys
CVE-2026-50522 is under active exploitation, allowing attackers to execute code remotely on vulnerable on-premises Microsoft SharePoint servers without authentication.
CISA recently flagged three actively exploited SharePoint vulnerabilities, but researchers have now also observed attacks targeting CVE-2026-50522.
Microsoft fixed the critical vulnerability in its July 2026 security updates.
Attackers Steal SharePoint Machine Keys
Hackers exploiting CVE-2026-50522 are stealing machine keys from compromised SharePoint servers.
SharePoint uses these keys to generate and validate authentication tokens. Attackers who obtain them can create valid tokens, impersonate legitimate users, and access SharePoint sites and stored documents.
Patching the vulnerable server may not remove this access. Stolen machine keys can continue validating forged authentication tokens after administrators install the security update.
Exploitation Began After Public PoC Release
Security researchers at watchTowr observed exploitation attempts shortly after a working proof-of-concept exploit became publicly available.
The company’s honeypot network recorded successful SharePoint compromises using the disclosed exploitation technique.
Defused also detected related SharePoint deserialization attacks as early as July 17.
PowerShell Exploit Is Publicly Available
A PowerShell proof-of-concept exploit for CVE-2026-50522 is now publicly available.
The exploit targets a SharePoint deserialization path to execute arbitrary code on the affected server. It sends a crafted authentication token containing a malicious .NET payload to a SharePoint sign-in endpoint.
Because the vulnerability requires no authentication, attackers can target exposed SharePoint servers remotely over the network.
Administrators Must Patch and Rotate Keys
Organizations running on-premises SharePoint should install the latest security updates immediately.
However, patching only closes the vulnerability. It does not remove authentication tokens, machine keys, or other access mechanisms that attackers may have obtained before the update.
Administrators with potentially exposed servers should rotate relevant machine keys and credentials. They should also investigate affected systems for unauthorized access, malicious payloads, and other signs of persistence.
In other security news, Hugging Face was recently breached, and OpenAI confirmed that one of its models was responsible after escaping a sandboxed testing environment.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages