Hackers are actively breaking into vulnerable on-premises Microsoft SharePoint servers and stealing secret machine keys that can let them keep impersonating users even after the software is patched. The flaw, CVE-2026-50522, is a critical unauthenticated remote-code-execution bug caused by unsafe deserialization in SharePoint's WS-Federation sign-in handling at /_trust/default.aspx. WatchTowr says exploitation started within hours of a public proof-of-concept release, and Defused saw related attack activity days earlier.
Why it matters: Organizations running on-premises SharePoint should treat this as urgent because patching alone may not remove attacker access if machine keys were stolen. Apply Microsoft's July updates immediately, then investigate for compromise and rotate affected keys and credentials.
Eduard Kovacs
2026.07.22
97% relevant
This article directly updates the same SharePoint event by confirming CVE-2026-50522 as the flaw seen in recent attacks, tying Defused’s earlier honeypot observations to the patched bug, and adding WatchTowr’s detail that attackers are stealing SharePoint machine keys to maintain long-term access even after patching.
Bill Toulas
2026.07.21
100% relevant
This article establishes a distinct story by tying real-world exploitation and persistence via stolen machine keys to CVE-2026-50522, rather than merely noting the flaw was patched or likely to be exploited.
← Back to all stories