# Critical SharePoint RCE flaw exploited to steal machine keys

_Tuesday, July 21, 2026 at 8:00 AM EDT · Security · Latest · Tier 2 — Notable_

![Critical SharePoint RCE flaw exploited to steal machine keys — Primary](https://www.bleepstatic.com/content/hl-images/2025/07/20/sharepoint-small-red-flare.jpg)

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.

Bill Toulas reported on July 21, 2026 that offensive security company watchTowr observed hackers leveraging the flaw against on-premise vulnerable SharePoint deployments immediately after a valid proof-of-concept exploit became public. On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability and within hours captured exploitation attempts using this PoC that successfully compromised target systems.

The researchers note that the attackers are stealing machine keys that allow them to maintain long-term access on breached systems. Early warning threat intelligence company Defused detected an undocumented SharePoint deserialization vector being used in attacks as early as July 17 but could not link the activity to a flaw.

Yesterday, the company said that the attacks were likely driven by exploiting the CVE-2026-50522 SharePoint vulnerability. At least one PowerShell demonstrative exploit for CVE-2026-50522 is available on GitHub from security researcher Janggggg. While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.

## Sources

- [Bleeping Computer](https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/)

---
Canonical: https://techandbusiness.org/newswire/m0ttS1SQ8wNcqwbItOJqfj
Retrieved: 2026-07-23T04:44:43.952Z
Publisher: Tech & Business (techandbusiness.org)
