Cybercriminals are exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to usurp machine keys and ensure persistent access even after affected servers are patched.
Microsoft details security issues related to an untrusted data deserialization vulnerability. This flaw enables remote attackers to execute unauthorized code over the network without requiring authentication.
This vulnerability was addressed in Microsoft’s July security update; however, it was initially not categorized as actively exploited. Recent advisories indicate that the threat potential is rising.
The offensive security firm watchTowr reported that attackers initiated exploitation of CVE-2026-50522 on vulnerable on-premises SharePoint systems shortly after a proof-of-concept (PoC) exploit became public.
“On July 20th, watchTowr identified a proof-of-concept exploit code for this vulnerability,” stated watchTowr. “Within hours, our global honeypot network, Attacker Eye, detected this PoC exploitation attempt and successfully breached the target system.”
Researchers report that attackers have stolen machine keys to ensure ongoing access to compromised environments.
Additionally, an early warning threat intelligence firm reported that as of July 17, an “undocumented SharePoint deserialization vector” was actively being utilized in attacks, although it could not be definitively linked to the outlined flaw.
Yesterday, the firm noted that the attack is likely attributable to the exploitation of the SharePoint vulnerability CVE-2026-50522.
Published Exploit
A PowerShell demonstration exploit for CVE-2026-50522 is circulating on GitHub, presented by security researcher Jangggg.
This PoC aims to trigger remote code execution by sending a malicious .NET ‘BinaryFormatter’ payload as a forged ‘SecurityContextToken’ cookie during a WS-Federation sign-in response to SharePoint’s ‘/_trust/default.aspx’ endpoint.
If the token is processed through an exploitable deserialization pathway, the payload can execute arbitrary code on the SharePoint server.
While BleepingComputer has yet to validate the PoC exploit, it appears architecturally sound and technically feasible.
It’s important to note that Jangggg published this PoC the same day that watchTowr began observing exploitation attempts, although it’s unclear if the security incidents utilized publicly available exploits.
While applying the latest SharePoint security updates will mitigate this vulnerability, watchTowr advises that organizations should also rotate credentials for any potentially exposed systems.
Security teams document only 54% of successful attacks and issue warnings for merely 14%. The remaining incidents go undetected in the environment.
Picus’ whitepaper demonstrates how to test your SIEM and EDR rules in breach and attack simulations to ensure that threats are not overlooked.
Source: www.bleepingcomputer.com




