Critical SharePoint RCE flaw exploited to steal machine keys
ID: b1ff5c9c-6c9e-5627-9251-85ee4c4da74a
STIX ID: report--b1ff5c9c-6c9e-5627-9251-85ee4c4da74a
Feed Name: Bleeping Computer
Microsoft SharePoint CVE-2026-50522, a critical deserialization RCE, is being actively exploited in the wild: attackers are leveraging a publicly released proof-of-concept to achieve remote code execution on on-prem SharePoint servers and steal machine keys that allow forging authentication tokens and long-term access. Security firms watchTowr and Defused observed exploitation soon after the PoC publication; Microsoft issued patches in July and defenders are advised to patch and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
