Critical SharePoint RCE flaw exploited to steal machine keys - BleepingComputer

What the report says
BleepingComputer reported that attackers are actively exploiting CVE-2026-50522, a critical Microsoft SharePoint remote code execution vulnerability, to steal machine keys from vulnerable on-premises servers. According to the report, those keys can let an attacker create apparently valid authentication tokens, potentially enabling impersonation of users and access to SharePoint sites, documents and other resources under the forged identity’s permissions.
Microsoft describes the issue as a deserialization of untrusted data vulnerability that can allow unauthenticated remote code execution over a network. The company fixed the flaw in its July security updates, but BleepingComputer noted that Microsoft’s advisory did not list it as already exploited at the time, instead flagging a higher likelihood of exploitation.
The article cited offensive security firm watchTowr, which said it saw attacks against vulnerable on-premises SharePoint deployments shortly after proof-of-concept exploit code became public on July 20. watchTowr said its honeypot network captured attempts that used the proof of concept and resulted in compromised systems. BleepingComputer also cited threat intelligence company Defused, which reported seeing an undocumented SharePoint deserialization vector as early as July 17 and later assessed the activity was likely tied to CVE-2026-50522.
BleepingComputer said at least one demonstrative PowerShell exploit was available on GitHub and described how it attempts to deliver a malicious .NET BinaryFormatter payload through a forged WS-Federation sign-in response. The outlet said it did not test the code, and it remains unclear whether observed attacks used that specific public exploit. Beyond installing Microsoft’s patches, watchTowr advised organizations to rotate credentials on systems that may have been exposed.
Loading debate for this article…
Other publishers covering this story
No additional verified coverage is currently clustered with this report.

Al‑Qaida and the Islamic State are both adopting AIThe Independent Uganda
256 Heart: a privacy-first relationship platform for verified adult connections in Uganda256 Heart
Nintendo reveals Zelda: Ocarina of Time remake price on Switch 2 - Nintendo EverythingNintendoeverything.com
Labor Day is a great time to save on MacBooks, iPads, AirPods and Apple Watches - CNNCNN
Nintendo Reveals What To Expect From The Zelda 40th Anniversary Direct - Nintendo LifeNintendo Life
Arjun's gameplay trailer for Street Fighter 6, releases in October - EventHubsEventHubs