SharePoint flaw CVE-2026-50522 under attack after public PoC goes live

Attackers are exploiting a critical SharePoint RCE vulnerability to steal machine keys, and patching alone won't lock them out.

CSBadmin
2 Min Read

Microsoft’s July security patches fixed CVE-2026-50522, a critical deserialization flaw in SharePoint that earned a 9.8 CVSS score. Days later, public exploit code appeared, and attackers began using it to compromise on-premises SharePoint servers in a single HTTP request.

watchTowr researchers observed exploitation attempts hitting their honeypot network within hours of the PoC release on July 20. The attackers are using the bug to pull IIS machine keys from target servers in one request. That detail matters because patching alone does not revoke keys the attacker already stole — anyone holding those keys retains persistent access to the SharePoint environment regardless of whether the vulnerability itself is closed.

Security firm Defused Cyber spotted exploitation as early as July 17, before the PoC went public. The requests carried no authentication tokens, confirming the findings that CVE-2026-50522 can be triggered without any login credentials. The vulnerability was originally demonstrated at Pwn2Own Berlin, meaning Microsoft had a working exploit in hand at the time of patching.

Censys has mapped roughly 1,500 internet-facing on-premises SharePoint servers, mostly running SharePoint 2019 and concentrated in the US. Teams should apply the July update and rotate machine keys on any exposed SharePoint infrastructure to block follow-on access.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.