Updated
Updated · The Hacker News · Jul 21
Hackers Exploit SharePoint RCE CVE-2026-50522 Rated 9.8, Stealing Keys After PoC Release
Updated
Updated · The Hacker News · Jul 21

Hackers Exploit SharePoint RCE CVE-2026-50522 Rated 9.8, Stealing Keys After PoC Release

3 articles · Updated · The Hacker News · Jul 21

Summary

  • watchTowr said attackers are now actively exploiting CVE-2026-50522 against on-premises SharePoint, using a public proof-of-concept to pull machine keys in a single request and keep persistent access.
  • The flaw carries a 9.8 CVSS score and lets remote attackers execute code; Microsoft said exploitation was more likely, though its advisory described the bug as requiring Site Owner-level authentication.
  • Defused Cyber said captured requests to a SharePoint sign-in endpoint contained no authentication material, suggesting threat actors are delivering a .NET deserialization payload through an unauthenticated path.
  • CVE-2026-50522 is the third July-patched SharePoint bug to see active abuse after CVE-2026-56164 and CVE-2026-58644, both exploited as zero-days before fixes.
  • CISA has warned multiple SharePoint flaws are being chained across supported on-premises versions—Subscription Edition, 2019 and 2016—for RCE, IIS key theft, persistence and malware deployment.

Insights

Your SharePoint is patched, but are attackers still inside your network using stolen keys?
With critical SharePoint flaws now a recurring crisis, is the on-premise model fundamentally insecure?