SharePoint deserialization flaw used to steal machine keys and sustain access after patching

1 min read
Source: BleepingComputer
SharePoint deserialization flaw used to steal machine keys and sustain access after patching
Photo: BleepingComputer
TL;DR Summary

Security researchers warn that the critical SharePoint deserialization flaw CVE-2026-50522 is being exploited to steal machine keys, enabling attackers to forge tokens and linger on-premises deployments even after patches; PoC exploits circulated online, prompting defenders to apply July updates and rotate credentials to limit exposure.

Share this article

Reading Insights

Total Reads

1

Unique Readers

4

Time Saved

3 min

vs 4 min read

Condensed

93%

65445 words

Want the full story? Read the original article

Read on BleepingComputer