Particle.news
Download on the App Store

Public PoC Drives Active Exploitation of Critical SharePoint RCE

Security teams should rotate IIS machine keys and exposed credentials because patching alone may not evict attackers.

Overview

  • A proof‑of‑concept exploit published on July 20 prompted active, in‑the‑wild attacks within hours that were observed by multiple security teams using global honeypots.
  • The flaw, CVE‑2026‑50522, is a .NET deserialization bug that can give remote code execution with a CVSS score of 9.8 and Microsoft released a patch in mid‑July.
  • Researchers report attackers are extracting SharePoint/IIS machine keys in a single request so they can forge authentication tokens and keep access even after servers are patched.
  • Advisories from Microsoft, CISA and multiple vendors say organizations must apply the July updates, hunt for intrusion artifacts, rotate machine keys and other exposed credentials, and monitor sign‑in and trust endpoints.
  • The exploit is part of a larger campaign targeting internet‑facing on‑premises SharePoint servers that has already seen several related vulnerabilities added to CISA’s Known Exploited Vulnerabilities list and raises risk of long‑term data theft or further malware deployment for unpatched systems.