Widespread Exploitation of Microsoft SharePoint
ID: c4b1a865-9447-5aca-8ad0-ad41de92ca22
STIX ID: report--c4b1a865-9447-5aca-8ad0-ad41de92ca22
Feed Name: Kudelski Security
Public reporting documents active exploitation of CVE-2026-50522, a critical (CVSS 9.8) deserialization flaw in Microsoft SharePoint Server's claims-based authentication endpoint (/ _trust/default.aspx) that enables remote code execution. Attackers have used a publicly released PoC to deploy malicious .NET assemblies and web shells, extract machine keys, and maintain persistence across at least 25 victims; Microsoft released patches and CISA added the CVE to its KEV catalog. Organizations are advised to patch affected SharePoint builds immediately, restrict access to the endpoint, rotate machine keys if compromised, monitor for abnormal HTTP requests and reflective .NET assembly loads in w3wp.exe, and conduct forensic threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
