Critical SharePoint RCE flaw exploited to steal machine keys - BleepingComputer

What the report says
BleepingComputer reported that attackers are actively exploiting CVE-2026-50522, a critical Microsoft SharePoint remote code execution vulnerability, to steal machine keys from vulnerable on-premises servers. According to the report, those keys can let an attacker create apparently valid authentication tokens, potentially enabling impersonation of users and access to SharePoint sites, documents and other resources under the forged identity’s permissions.
Microsoft describes the issue as a deserialization of untrusted data vulnerability that can allow unauthenticated remote code execution over a network. The company fixed the flaw in its July security updates, but BleepingComputer noted that Microsoft’s advisory did not list it as already exploited at the time, instead flagging a higher likelihood of exploitation.
The article cited offensive security firm watchTowr, which said it saw attacks against vulnerable on-premises SharePoint deployments shortly after proof-of-concept exploit code became public on July 20. watchTowr said its honeypot network captured attempts that used the proof of concept and resulted in compromised systems. BleepingComputer also cited threat intelligence company Defused, which reported seeing an undocumented SharePoint deserialization vector as early as July 17 and later assessed the activity was likely tied to CVE-2026-50522.
BleepingComputer said at least one demonstrative PowerShell exploit was available on GitHub and described how it attempts to deliver a malicious .NET BinaryFormatter payload through a forged WS-Federation sign-in response. The outlet said it did not test the code, and it remains unclear whether observed attacks used that specific public exploit. Beyond installing Microsoft’s patches, watchTowr advised organizations to rotate credentials on systems that may have been exposed.
Loading debate for this article…
Other publishers covering this story
No additional verified coverage is currently clustered with this report.

AI platforms accelerating Uganda’s digital transformationThe Observer
Two MacBooks and an agent named BudThe Observer
La Fang Eco Resort hosts influencers to promote Dolwe Island tourismNile Post
How young is too young for AI?The Independent Uganda
Roku raises streaming stick prices by up to 60 percent - Ars TechnicaArs Technica
'See You in the Sequel': Halo 2 Remake All But Confirmed - Push SquarePush Square