Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Critical SharePoint RCE flaw exploited to steal machine keys

    July 21, 2026

    What Does Olive Garden’s Never-Ending Pasta Have to Do With Voting Rights?

    July 21, 2026

    The OSINT Newsletter – Issue #115

    July 21, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Critical SharePoint RCE flaw exploited to steal machine keys
    News

    Critical SharePoint RCE flaw exploited to steal machine keys

    adminBy adminJuly 21, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Critical SharePoint RCE flaw exploited to steal machine keys

    Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.

    An attacker obtaining them can create valid authentication tokens to impersonate users and access available resources such as SharePoint sites and documents with the privileges of the forged identity.

    Microsoft describes the security issue as a deserialization-of-untrusted-data flaw that allows a remote attacker to execute code over a network without authentication.

    image

    The flaw was addressed in July’s security updates from Microsoft. It was not marked as actively exploited, but the advisory noted an increased likelihood of being leveraged.

    Offensive security company watchTowr has observed that hackers started to leverage CVE-2026-50522 against on-premise vulnerable SharePoint deployments, immediately after a valid proof-of-concept (PoC) exploit became public.

    “On July 20th, watchTowr identified proof-of-concept exploit code for this vulnerability,” watchTowr states. “Within hours, our global honeypot network, Attacker Eye, captured exploitation attempts using this PoC that successfully compromised target systems.”

    The researchers note that the attackers are stealing machine keys that allow them to maintain long-term access on breached systems.

    Early warning threat intelligence company Defused detected “an undocumented SharePoint deserialization vector” being used in attacks as early as July 17 but could not link the activity to a flaw.

    Yesterday, the company said that the attacks were likely driven by exploiting the CVE-2026-50522 SharePoint vulnerability.

    Exploit released publicly

    At least one PowerShell demonstrative exploit for CVE-2026-50522 is available on GitHub from security researcher Janggggg.

    The PoC attempts to trigger remote code execution by delivering a malicious .NET ‘BinaryFormatter’ payload as the cookie of a forged ‘SecurityContextToken’ within a WS-Federation sign-in response posted to SharePoint’s ‘/_trust/default.aspx’ endpoint.

    If the token is processed by a vulnerable deserialization path, the payload results in arbitrary code execution on the SharePoint server.

    BleepingComputer did not test the PoC exploit, but it looks structurally and technically legitimate.

    It should be noted that Janggggg’s published the PoC on the same day watchTowr started to detect attacks leveraging it. However, it is unclear if the observed incidents made use of the publicly available exploit.

    While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhat Does Olive Garden’s Never-Ending Pasta Have to Do With Voting Rights?
    admin
    • Website

    Related Posts

    News

    What Does Olive Garden’s Never-Ending Pasta Have to Do With Voting Rights?

    July 21, 2026
    News

    The OSINT Newsletter – Issue #115

    July 21, 2026
    News

    Apple Fixes Hide My Email Vulnerability After 404 Media Coverage

    July 21, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202636 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202636 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Critical SharePoint RCE flaw exploited to steal machine keys

    July 21, 2026

    What Does Olive Garden’s Never-Ending Pasta Have to Do With Voting Rights?

    July 21, 2026

    The OSINT Newsletter – Issue #115

    July 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.