CVE Tools
Back to feed
Exploited in the wild SharePoint rce Microsoft malware

Critical SharePoint RCE flaw exploited to steal machine keys

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

A critical remote code execution (RCE) vulnerability in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to steal sensitive machine keys. These stolen keys enable adversaries to forge authentication tokens and gain unauthorized access to SharePoint resources under compromised identities. Microsoft classified the flaw as a deserialization-of-untrusted-data issue that allows unauthenticated remote code execution. The vulnerability was patched in July’s updates but had not been flagged as exploited at the time. Offensive security firm watchTowr reported observing real-world exploitation attempts shortly after a proof-of-concept (PoC) exploit surfaced online. A PowerShell-based PoC for CVE-2026-50522 has since been shared on GitHub, demonstrating how attackers can deliver malicious payloads via a WS-Federation sign-in response. While patching mitigates the risk, experts recommend rotating credentials for any potentially exposed assets.