Particle.news
Download on the App Store

Public PoC Triggers Active Exploitation of Critical SharePoint RCE

Attackers are stealing IIS and SharePoint machine keys to stay inside networks after fixes, so applying patches alone will not guarantee removal of intruders.

Overview

  • Security teams observed active exploitation of CVE-2026-50522 shortly after a public proof-of-concept was posted on July 20, with honeypots capturing attack attempts within hours.
  • CVE-2026-50522 is a critical .NET deserialization flaw in on-premises Microsoft SharePoint that can grant remote code execution and was assigned a CVSS score of 9.8 and an 'Exploitation More Likely' tag by Microsoft.
  • Researchers say attackers can trigger the bug by delivering a malicious BinaryFormatter payload inside a forged WS-Fed sign-in token, letting them run code on vulnerable SharePoint servers without valid credentials.
  • Observers report intruders are extracting IIS/SharePoint machine keys in a single request so they can forge authentication tokens and retain access even after servers are patched.
  • Microsoft issued patches in July and agencies including CISA and vendors urge immediate patching plus rotation of machine keys and credentials, forensic hunts for indicators of compromise, and other post-patch remediation to evict persistent actors.