logo

Widespread Exploitation of Microsoft SharePoint

ID: c4b1a865-9447-5aca-8ad0-ad41de92ca22

STIX ID: report--c4b1a865-9447-5aca-8ad0-ad41de92ca22

Feed Name: Kudelski Security

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-27

...
...

Public reporting documents active exploitation of CVE-2026-50522, a critical (CVSS 9.8) deserialization flaw in Microsoft SharePoint Server's claims-based authentication endpoint (/ _trust/default.aspx) that enables remote code execution. Attackers have used a publicly released PoC to deploy malicious .NET assemblies and web shells, extract machine keys, and maintain persistence across at least 25 victims; Microsoft released patches and CISA added the CVE to its KEV catalog. Organizations are advised to patch affected SharePoint builds immediately, restrict access to the endpoint, rotate machine keys if compromised, monitor for abnormal HTTP requests and reflective .NET assembly loads in w3wp.exe, and conduct forensic threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.