Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
An attacker obtaining them can create valid authentication tokens to impersonate users and access available resources such as SharePoint sites and documents with the privileges of the forged identity.
Microsoft describes the security issue as a deserialization-of-untrusted-data flaw that allows a remote attacker to execute code over a network without authentication.
The flaw was addressed in July's security updates from Microsoft. It was not marked as actively exploited, but the advisory noted an increased likelihood of being leveraged.
Offensive security company watchTowr has observed that hackers started to leverage CVE-2026-50522 against on-premise vulnerable SharePoint deployments, immediately after a valid proof-of-concept (PoC) exploit became public.
βOn July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability,β watchTowr states. "Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems."
The researchers note that the attackers are stealing machine keys that allow them to maintain long-term access on breached systems.
Early warning threat intelligence company Defused detected "an undocumented SharePoint deserialization vector" being used in attacks as early as July 17 but could not link the activity to a flaw.
Yesterday, the company said that the attacks were likely driven by exploiting the CVE-2026-50522 SharePoint vulnerability.
Exploit released publicly
... continue reading