Skip to main content
Security

Critical SharePoint RCE flaw exploited to steal machine keys

Critical SharePoint RCE flaw exploited to steal machine keys Image: Primary
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. Bill Toulas reported on July 21, 2026 that offensive security company watchTowr observed hackers leveraging the flaw against on-premise vulnerable SharePoint deployments immediately after a valid proof-of-concept exploit became public. On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability and within hours captured exploitation attempts using this PoC that successfully compromised target systems. The researchers note that the attackers are stealing machine keys that allow them to maintain long-term access on breached systems. Early warning threat intelligence company Defused detected an undocumented SharePoint deserialization vector being used in attacks as early as July 17 but could not link the activity to a flaw. Yesterday, the company said that the attacks were likely driven by exploiting the CVE-2026-50522 SharePoint vulnerability. At least one PowerShell demonstrative exploit for CVE-2026-50522 is available on GitHub from security researcher Janggggg. While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bleeping Computer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Capital
AI Capital

Scan.com raises $220 million across equity and debt financing

Scan.com has raised $220 million in financing, comprising a $90 million Series C equity round and $130 million in debt facilities. The company uses AI to match patient referrals with imaging centers according to availability, pric...

Security
Security

Brave releases patch for reported exploited V8 flaw

Brave released desktop version 1.94.121 with a fix for CVE-2026-85046, a Chromium V8 JavaScript-engine vulnerability the company said had been exploited in the wild. The browser maker urged users to install the update and relaunch...

Security AI
Security AI

Microsoft reports ASCII-smuggling use in email spam

Microsoft said email spammers are adopting ASCII smuggling, a technique used to conceal malicious instructions in AI-agent prompt-injection attacks, to evade email-platform filters. The reported shift applies the obfuscation techn...

Security Policy
Security Policy

US and UK sign scam-center information-sharing agreement

The United States and United Kingdom have signed a memorandum of understanding to investigate organized crime syndicates behind online scam centers and share information. The initiative targets centers, many based in Southeast Asi...

Science
Science

Study links unusual ZrTe5 oscillations to reentrant Landau levels

Researchers studying zirconium pentatelluride reported quantum oscillations that persisted beyond the quantum limit under magnetic fields up to 60 tesla and temperatures near 0.7 kelvin. Their experiments and calculations attribut...

Security
Security

CrowdStrike investigates Falcon privilege-escalation zero-day

CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform. The expl...