Hackers are actively breaking into vulnerable on-premises Microsoft SharePoint servers and stealing secret machine keys that can let them keep impersonating users even after the software is patched. The flaw, CVE-2026-50522, is a critical unauthenticated remote-code-execution bug caused by unsafe deserialization in SharePoint's WS-Federation sign-in handling at /_trust/default.aspx. WatchTowr says exploitation started within hours of a public proof-of-concept release, and Defused saw related attack activity days earlier.
info@thehackernews.com (The Hacker News)
2026.08.11
78% relevant
This appears to add technical detail about the same SharePoint attack path by describing an exploit chain that reaches unauthenticated remote code execution and discussing how the chain was developed or demonstrated, likely expanding on exploitation mechanics and post-compromise persistence risk.
Lawrence Abrams
2026.08.06
55% relevant
This article adds a real-world victim case: Switzerland’s federal IT office says attackers breached its SharePoint environment, compromised about 200 accounts, and suspects exploitation of the mid-July SharePoint flaws fixed by Microsoft, possibly including CVE-2026-50522, though the exact bug is not yet confirmed.
2026.08.04
88% relevant
This article provides a real-world victim disclosure tied to the July SharePoint server attacks, adding that Switzerland's BIT saw about 200 compromised user and technical accounts on on-premises SharePoint and suspects the same July SharePoint flaws. It also reinforces the persistence risk described in the tracked story by noting guidance to rotate IIS machine keys and rebuild affected servers, not just patch.
Eduard Kovacs
2026.07.22
97% relevant
This article directly updates the same SharePoint event by confirming CVE-2026-50522 as the flaw seen in recent attacks, tying Defused’s earlier honeypot observations to the patched bug, and adding WatchTowr’s detail that attackers are stealing SharePoint machine keys to maintain long-term access even after patching.
Bill Toulas
2026.07.21
100% relevant
This article establishes a distinct story by tying real-world exploitation and persistence via stolen machine keys to CVE-2026-50522, rather than merely noting the flaw was patched or likely to be exploited.