Critical SharePoint RCE flaw exploited to steal machine keys
Summary
Hackers are actively exploiting a critical vulnerability (CVE-2026-50522) in Microsoft SharePoint to steal machine keys and maintain persistent access. This allows attackers to bypass patches and remain on compromised servers.
IFF Assessment
This vulnerability allows attackers to steal machine keys and maintain persistence, posing a significant threat to organizations.
Severity
This critical RCE vulnerability in SharePoint allows for remote code execution, leading to authentication bypass and potential theft of sensitive information like machine keys, indicating a high severity and exploitability.
Defender Context
This exploitation highlights the need for prompt patching of Microsoft SharePoint servers and enhanced monitoring for signs of persistence. Defenders should be aware of techniques used to steal machine keys and look for anomalous access patterns even after patching.