Critical SharePoint RCE flaw exploited to steal machine keys

Summary

Hackers are actively exploiting a critical vulnerability (CVE-2026-50522) in Microsoft SharePoint to steal machine keys and maintain persistent access. This allows attackers to bypass patches and remain on compromised servers.

IFF Assessment

FOE

This vulnerability allows attackers to steal machine keys and maintain persistence, posing a significant threat to organizations.

Severity

9.8 Critical

This critical RCE vulnerability in SharePoint allows for remote code execution, leading to authentication bypass and potential theft of sensitive information like machine keys, indicating a high severity and exploitability.

Defender Context

This exploitation highlights the need for prompt patching of Microsoft SharePoint servers and enhanced monitoring for signs of persistence. Defenders should be aware of techniques used to steal machine keys and look for anomalous access patterns even after patching.

Read Full Story →