Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Summary

A fourth SharePoint vulnerability, CVE-2026-50522, is being actively exploited by threat actors. Attackers are leveraging this flaw to steal machine keys, enabling them to maintain persistent, long-term access to compromised systems.

IFF Assessment

FOE

The active exploitation of a critical vulnerability by threat actors to gain persistent access represents a direct threat to organizations' security.

Severity

9.8 Critical

This score reflects a critical severity, considering the potential for high impact on confidentiality, integrity, and availability due to persistent access and theft of sensitive information like machine keys. The lack of specified attack vector or complexity suggests it's easily exploitable.

Defender Context

This highlights the ongoing risk posed by unpatched vulnerabilities in widely used software like SharePoint. Defenders must prioritize timely patching and implement robust monitoring to detect and respond to exploitation attempts, particularly those that grant persistent access.

Read Full Story →