Attackers are actively exploiting a critical SharePoint RCE flaw to steal machine keys from vulnerable on-premise servers. The issue, tracked as CVE-2026-50522, can give criminals a lasting route back into compromised environments.

Microsoft fixed the vulnerability in its July security updates. However, security researchers now report exploitation attempts against unpatched SharePoint deployments.

The attacks can create a serious persistence risk. Even after an organisation applies the update, stolen machine keys may still allow attackers to access affected systems.

Attackers Can Forge Authentication Tokens

CVE-2026-50522 is a deserialisation vulnerability involving untrusted data. An unauthenticated attacker can exploit the flaw over a network and execute code remotely on a vulnerable server.

Researchers say attackers are targeting machine keys after gaining access. These keys can help an intruder create valid authentication tokens.

As a result, attackers may impersonate legitimate users. They could then access SharePoint sites, documents, and other resources available to the forged account.

The level of access depends on the permissions assigned to the impersonated identity. Nevertheless, a high-privilege account could expose sensitive company data and internal systems.

Exploitation Began Soon After PoC Release

Security teams observed exploitation attempts within hours of a proof-of-concept becoming public. The activity targeted vulnerable on-premise SharePoint environments.

Researchers had also detected an unusual SharePoint deserialisation technique several days earlier. At first, they could not connect the attacks to a known vulnerability.

They later assessed that CVE-2026-50522 likely drove the activity. This suggests attackers may have begun testing possible attack paths before the public exploit appeared.

A publicly available demonstration shows how the flaw could work. It uses a forged sign-in response that carries a malicious .NET payload to a SharePoint endpoint.

If a vulnerable server processes the token through the affected deserialisation path, the payload can trigger remote code execution. Attackers could then run commands on the server without valid credentials.

Patching Alone May Not Remove Access

Installing Microsoft’s July updates removes the SharePoint RCE flaw. However, patching may not fully resolve an incident where attackers have already stolen machine keys.

Organisations should rotate credentials and keys on systems that may have been exposed. They should also investigate unusual authentication activity and review access to SharePoint services.

Security teams should prioritise internet-facing SharePoint servers. In addition, they should look for suspicious sign-in events, unexpected token activity, and unexplained administrative changes.

Conclusion

The SharePoint RCE flaw presents an urgent risk for organisations running vulnerable on-premise servers. Prompt patching is essential, but incident response must go further. Companies should rotate potentially exposed credentials and check for signs that attackers have retained access.


0 responses to “SharePoint RCE Flaw Exploited to Steal Machine Keys”