Attackers exploit Microsoft SharePoint RCE flaw CVE-2026-50522 to steal machine keys and keep access after patching

Hackers are actively breaking into vulnerable on-premises Microsoft SharePoint servers and stealing secret machine keys that can let them keep impersonating users even after the software is patched. The flaw, CVE-2026-50522, is a critical unauthenticated remote-code-execution bug caused by unsafe deserialization in SharePoint's WS-Federation sign-in handling at /_trust/default.aspx. WatchTowr says exploitation started within hours of a public proof-of-concept release, and Defused saw related attack activity days earlier.
Why it matters: Organizations running on-premises SharePoint should treat this as urgent because patching alone may not remove attacker access if machine keys were stolen. Apply Microsoft's July updates immediately, then investigate for compromise and rotate affected keys and credentials.

Sources

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
Eduard Kovacs 2026.07.22 97% relevant
This article directly updates the same SharePoint event by confirming CVE-2026-50522 as the flaw seen in recent attacks, tying Defused’s earlier honeypot observations to the patched bug, and adding WatchTowr’s detail that attackers are stealing SharePoint machine keys to maintain long-term access even after patching.
Critical SharePoint RCE flaw exploited to steal machine keys
Bill Toulas 2026.07.21 100% relevant
This article establishes a distinct story by tying real-world exploitation and persistence via stolen machine keys to CVE-2026-50522, rather than merely noting the flaw was patched or likely to be exploited.
← Back to all stories