Skip to main content
Back to Newswire
Security

Critical SharePoint RCE flaw exploited to steal machine keys

Critical SharePoint RCE flaw exploited to steal machine keys Image: Primary
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. Bill Toulas reported on July 21, 2026 that offensive security company watchTowr observed hackers leveraging the flaw against on-premise vulnerable SharePoint deployments immediately after a valid proof-of-concept exploit became public. On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability and within hours captured exploitation attempts using this PoC that successfully compromised target systems. The researchers note that the attackers are stealing machine keys that allow them to maintain long-term access on breached systems. Early warning threat intelligence company Defused detected an undocumented SharePoint deserialization vector being used in attacks as early as July 17 but could not link the activity to a flaw. Yesterday, the company said that the attacks were likely driven by exploiting the CVE-2026-50522 SharePoint vulnerability. At least one PowerShell demonstrative exploit for CVE-2026-50522 is available on GitHub from security researcher Janggggg. While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.