Tag

Cve 2026 50522

All articles tagged with #cve 2026 50522

SharePoint deserialization flaw used to steal machine keys and sustain access after patching
security1 month ago

SharePoint deserialization flaw used to steal machine keys and sustain access after patching

Security researchers warn that the critical SharePoint deserialization flaw CVE-2026-50522 is being exploited to steal machine keys, enabling attackers to forge tokens and linger on-premises deployments even after patches; PoC exploits circulated online, prompting defenders to apply July updates and rotate credentials to limit exposure.

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522
security1 month ago

Public PoC Sparks Active Exploitation of Critical SharePoint RCE CVE-2026-50522

Microsoft patched CVE-2026-50522, a critical deserialization-based RCE in SharePoint Server, but a public PoC and threat intel indicate active exploitation of on‑prem deployments. The flaw allows remote code execution over the network, potentially by an attacker authenticated as a Site Owner, enabling arbitrary code execution and theft of IIS machine keys for persistence. Defenders should rotate credentials and deploy patches; CISA warns that multiple SharePoint vulnerabilities are being exploited across supported on‑premises versions.