logo

CVE-2026-50522 PoC Fuels SharePoint Attacks

ID: ec5c9a5c-0548-5c72-82f3-e63368b7db5b

STIX ID: report--ec5c9a5c-0548-5c72-82f3-e63368b7db5b

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2026-07-22

Date Updated: 2026-07-25

Author: ameer

...
...

This report covers CVE-2026-50522, a critical (CVSS 9.8) deserialization vulnerability in on-premises Microsoft SharePoint Server that became actively exploited shortly after public PoC release; attackers are reported to be using a forged token to deliver a BinaryFormatter payload to /_trust/default.aspx and attempting to exfiltrate SharePoint machine keys for persistent access. The document lists affected SharePoint versions, describes observed exploitation and timelines, highlights the post-compromise risk of stolen machine keys, and recommends urgent actions: apply Microsoft’s July patches, hunt for intrusion artifacts, rotate machine keys after investigation, review authentication and logs, and validate persistence and privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.