Overview
- Security teams observed active exploitation of CVE-2026-50522 shortly after a public proof-of-concept was posted on July 20, with honeypots capturing attack attempts within hours.
- CVE-2026-50522 is a critical .NET deserialization flaw in on-premises Microsoft SharePoint that can grant remote code execution and was assigned a CVSS score of 9.8 and an 'Exploitation More Likely' tag by Microsoft.
- Researchers say attackers can trigger the bug by delivering a malicious BinaryFormatter payload inside a forged WS-Fed sign-in token, letting them run code on vulnerable SharePoint servers without valid credentials.
- Observers report intruders are extracting IIS/SharePoint machine keys in a single request so they can forge authentication tokens and retain access even after servers are patched.
- Microsoft issued patches in July and agencies including CISA and vendors urge immediate patching plus rotation of machine keys and credentials, forensic hunts for indicators of compromise, and other post-patch remediation to evict persistent actors.