bleeping-computer · Crawled Jul 21, 2026
Critical SharePoint RCE flaw exploited to steal machine keys
2 IoCs
Read original article ↗
AI Summary
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys, enabling them to forge authentication tokens and maintain persistent access to compromised systems even after patching. The flaw, a deserialization-of-untrusted-data issue, allows unauthenticated remote code execution. Exploitation began shortly after a public proof-of-concept was released, with attackers targeting on-premise SharePoint deployments.
AI-extracted · verify before operational use