CVE-2026-50522 PoC Fuels SharePoint Attacks
ID: ec5c9a5c-0548-5c72-82f3-e63368b7db5b
STIX ID: report--ec5c9a5c-0548-5c72-82f3-e63368b7db5b
Feed Name: SOCRadar Blog
This report covers CVE-2026-50522, a critical (CVSS 9.8) deserialization vulnerability in on-premises Microsoft SharePoint Server that became actively exploited shortly after public PoC release; attackers are reported to be using a forged token to deliver a BinaryFormatter payload to /_trust/default.aspx and attempting to exfiltrate SharePoint machine keys for persistent access. The document lists affected SharePoint versions, describes observed exploitation and timelines, highlights the post-compromise risk of stolen machine keys, and recommends urgent actions: apply Microsoft’s July patches, hunt for intrusion artifacts, rotate machine keys after investigation, review authentication and logs, and validate persistence and privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
