Critical SharePoint RCE flaw exploited to steal machine keys

Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting CVE-2026-50522 in Microsoft SharePoint to steal machine keys and keep access even after patching. The attacks can enable forged authentication tokens, and the public PoC has been quickly used against vulnerable on-premises SharePoint servers. #CVE-2026-50522 #MicrosoftSharePoint #watchTowr #Defused #Janggggg

Keypoints

  • Hackers are exploiting CVE-2026-50522 in Microsoft SharePoint.
  • The flaw lets attackers steal machine keys for persistent access.
  • Forged authentication tokens can impersonate users and access SharePoint resources.
  • Microsoft fixed the issue in July security updates after warning of increased risk.
  • watchTowr and Defused observed exploitation soon after a public PoC appeared.

Read More: https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/