256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Critical SharePoint RCE flaw exploited to steal machine keys - BleepingComputer

Share
Critical SharePoint RCE flaw exploited to steal machine keys - BleepingComputer
Image · BleepingComputer

What the report says

BleepingComputer reported that attackers are actively exploiting CVE-2026-50522, a critical Microsoft SharePoint remote code execution vulnerability, to steal machine keys from vulnerable on-premises servers. According to the report, those keys can let an attacker create apparently valid authentication tokens, potentially enabling impersonation of users and access to SharePoint sites, documents and other resources under the forged identity’s permissions.

Microsoft describes the issue as a deserialization of untrusted data vulnerability that can allow unauthenticated remote code execution over a network. The company fixed the flaw in its July security updates, but BleepingComputer noted that Microsoft’s advisory did not list it as already exploited at the time, instead flagging a higher likelihood of exploitation.

The article cited offensive security firm watchTowr, which said it saw attacks against vulnerable on-premises SharePoint deployments shortly after proof-of-concept exploit code became public on July 20. watchTowr said its honeypot network captured attempts that used the proof of concept and resulted in compromised systems. BleepingComputer also cited threat intelligence company Defused, which reported seeing an undocumented SharePoint deserialization vector as early as July 17 and later assessed the activity was likely tied to CVE-2026-50522.

BleepingComputer said at least one demonstrative PowerShell exploit was available on GitHub and described how it attempts to deliver a malicious .NET BinaryFormatter payload through a forged WS-Federation sign-in response. The outlet said it did not test the code, and it remains unclear whether observed attacks used that specific public exploit. Beyond installing Microsoft’s patches, watchTowr advised organizations to rotate credentials on systems that may have been exposed.

Read the full report at BleepingComputer →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting