Critical SharePoint RCE flaw exploited to steal machine keys
Reported exploitedSharePointOur summary
A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to steal sensitive machine keys. These stolen keys enable adversaries to forge authentication tokens and gain unauthorized access to SharePoint resources under compromised identities. Microsoft classified the flaw as a deserialization-of-untrusted-data issue that allows unauthenticated remote code execution. The vulnerability was patched in July’s updates but had not been flagged as exploited at the time. Offensive security firm watchTowr reported observing real-world exploitation attempts shortly after a proof-of-concept (PoC) exploit surfaced online. A PowerShell-based PoC for CVE-2026-50522 has since been shared on GitHub, demonstrating how attackers can deliver malicious payloads via a WS-Federation sign-in response. While patching mitigates the risk, experts recommend rotating credentials for any potentially exposed assets.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.