Attackers exploit Microsoft SharePoint RCE flaw CVE-2026-50522 to steal machine keys and keep access after patching

Hackers are actively breaking into vulnerable on-premises Microsoft SharePoint servers and stealing secret machine keys that can let them keep impersonating users even after the software is patched. The flaw, CVE-2026-50522, is a critical unauthenticated remote-code-execution bug caused by unsafe deserialization in SharePoint's WS-Federation sign-in handling at /_trust/default.aspx. WatchTowr says exploitation started within hours of a public proof-of-concept release, and Defused saw related attack activity days earlier.
Why it matters: Organizations running on-premises SharePoint should treat this as urgent because patching alone may not remove attacker access if machine keys were stolen. Apply Microsoft's July updates immediately, then investigate for compromise and rotate affected keys and credentials.

Sources

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
info@thehackernews.com (The Hacker News) 2026.08.11 78% relevant
This appears to add technical detail about the same SharePoint attack path by describing an exploit chain that reaches unauthenticated remote code execution and discussing how the chain was developed or demonstrated, likely expanding on exploitation mechanics and post-compromise persistence risk.
Swiss government SharePoint breach compromised 200 accounts
Lawrence Abrams 2026.08.06 55% relevant
This article adds a real-world victim case: Switzerland’s federal IT office says attackers breached its SharePoint environment, compromised about 200 accounts, and suspects exploitation of the mid-July SharePoint flaws fixed by Microsoft, possibly including CVE-2026-50522, though the exact bug is not yet confirmed.
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
2026.08.04 88% relevant
This article provides a real-world victim disclosure tied to the July SharePoint server attacks, adding that Switzerland's BIT saw about 200 compromised user and technical accounts on on-premises SharePoint and suspects the same July SharePoint flaws. It also reinforces the persistence risk described in the tracked story by noting guidance to rotate IIS machine keys and rebuild affected servers, not just patch.
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
Eduard Kovacs 2026.07.22 97% relevant
This article directly updates the same SharePoint event by confirming CVE-2026-50522 as the flaw seen in recent attacks, tying Defused’s earlier honeypot observations to the patched bug, and adding WatchTowr’s detail that attackers are stealing SharePoint machine keys to maintain long-term access even after patching.
Critical SharePoint RCE flaw exploited to steal machine keys
Bill Toulas 2026.07.21 100% relevant
This article establishes a distinct story by tying real-world exploitation and persistence via stolen machine keys to CVE-2026-50522, rather than merely noting the flaw was patched or likely to be exploited.
← Back to all stories