Skip to content

SharePoint Vulnerability CVE-2026-50522: Attackers Steal Machine Keys for Persistent Access

The point: Attackers exploit CVE-2026-50522 to steal machine keys from SharePoint servers, enabling them to generate valid authentication tokens and maintain persistent access even after patching.

Immediately following the publication of functional exploit code for CVE-2026-50522, attackers are targeting local SharePoint installations. Security researchers observed the first successful compromises within hours of the Proof-of-Concept publication.

Microsoft patched the critical vulnerability CVE-2026-50522 in July 2026. watchTowr identified publicly available Proof-of-Concept code for the flaw on 20 July 2026. Within hours, watchTowr’s global honeypot network registered successful exploitation attempts that compromised target systems. The company Defused already detected suspicious deserialization activity against SharePoint systems on 17 July.

The attack leverages a deserialization flaw in the /_trust/default.aspx endpoint. The public exploit code prepares a binary payload in a forged authentication cookie within a WS-Federation login response. When this token is processed by the server, it executes arbitrary code – without requiring authentication. The technical risk for organizations lies in the immediate exploitability without preconditions.

The attackers’ business model consists of stealing machine keys from compromised SharePoint servers. With these keys, the actors can generate valid authentication tokens and authenticate as legitimate users. This grants them access to SharePoint sites and documents even after the vulnerability is patched – as long as the compromised keys are not renewed. Persistence is thus achieved through offline compromise of cryptographic material.

Microsoft released security updates in July 2026. Security experts recommend CISOs, in addition to applying the patch, immediately renew all credentials and keys on potentially affected SharePoint systems – particularly the machine keys that attackers have extracted. This measure is necessary to invalidate persistent token-based access.


Source: www.it-daily.net · Published 23 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: