Fourth SharePoint Flaw Exploited to Steal Machine Keys

CVE-2026-50522, patched by Microsoft on July 14, was exploited in July to extract SharePoint machine keys and maintain access, according to Defused and WatchTowr.
Security firms Defused and WatchTowr reported active exploitation of CVE-2026-50522, marking the fourth SharePoint vulnerability targeted in a month-long attack wave. Microsoft released a patch on July 14. Defused’s honeypots recorded exploitation attempts on July 17 and updated its analysis on July 20 to identify the likely target as CVE-2026-50522. WatchTowr confirmed attacks shortly after proof-of-concept exploit code became public.
Microsoft’s advisory describes CVE-2026-50522 as a critical remote code execution flaw that results from deserialization of untrusted data. The advisory explains that in a network-based attack an adversary authenticated with at least Site Owner privileges could write and execute arbitrary code on a SharePoint Server.
WatchTowr reported that attackers are extracting SharePoint machine keys with a single request, a method used to retain long-term access to compromised servers. The firm warned that applying the patch alone may not remove attackers who already obtained machine keys and recommended rotating credentials on any exposed assets.
Three other SharePoint vulnerabilities with exploitation reported in recent weeks are CVE-2026-58644, CVE-2026-56164 and CVE-2026-45659. The Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog currently lists 13 SharePoint flaws, five of which were added this year; CVE-2026-50522 has not yet been added to that list.
Administrators should confirm that Microsoft’s July updates are installed on SharePoint servers, check logs and configurations for signs of unauthorized access or key exfiltration, rotate machine keys and service account credentials tied to affected systems, and monitor for unusual requests that could indicate further activity while conducting forensic analysis.





