CVE Tools

Critical SharePoint RCE flaw exploited to steal machine keys

BleepingComputerBy Bill Toulas

Reported exploitedSharePoint

Our summary

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to steal sensitive machine keys. These stolen keys enable adversaries to forge authentication tokens and gain unauthorized access to SharePoint resources under compromised identities. Microsoft classified the flaw as a deserialization-of-untrusted-data issue that allows unauthenticated remote code execution. The vulnerability was patched in July’s updates but had not been flagged as exploited at the time. Offensive security firm watchTowr reported observing real-world exploitation attempts shortly after a proof-of-concept (PoC) exploit surfaced online. A PowerShell-based PoC for CVE-2026-50522 has since been shared on GitHub, demonstrating how attackers can deliver malicious payloads via a WS-Federation sign-in response. While patching mitigates the risk, experts recommend rotating credentials for any potentially exposed assets.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store