Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server vulnerability this month is under active exploitation, with attackers using a public PoC to steal machine keys and maintain persistence, patching alone does not close the exposure.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
Enterprise server room with rack-mounted equipment and a glowing red status indicator under dim industrial lighting.

Enterprise server room with rack-mounted equipment and a glowing red status indicator under dim industrial lighting.

A third SharePoint Server vulnerability patched during Microsoft's July 2026 Patch Tuesday has come under active exploitation, according to security firm watchTowr, which says attackers are already using a public proof of concept to steal machine keys from vulnerable servers and maintain persistent access long after the initial breach.

The flaw itself, CVE-2026-50522, carries a CVSS score of 9.8 and stems from a deserialization of untrusted data issue in Microsoft Office SharePoint. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting it.

In practical terms, an attacker who has authenticated to a SharePoint environment with at least Site Owner permissions can write and execute arbitrary code remotely on the server itself. Microsoft's own advisory rates the attack vector as network based and the attack complexity as low, meaning an attacker does not need deep prior knowledge of the target environment and can repeat the exploit reliably once they understand the payload. The company has since tagged the vulnerability with an "Exploitation More Likely" assessment, which in hindsight was an understatement.

What makes this genuinely urgent, rather than simply another CVE to add to a patching queue, is what watchTowr observed once a public proof of concept became available. Attackers are pulling SharePoint machine keys through a single, straightforward request.

Machine keys are cryptographic values SharePoint and the underlying ASP.NET framework use to validate the integrity of authentication tokens, session state, and view state data passed between the server and connected clients. Once an attacker has a valid machine key, they can forge tokens the server will treat as legitimate, effectively minting their own persistent access independent of any password or account they originally compromised.

watchTowr's warning on this point is blunt: patching the vulnerability itself does nothing to invalidate keys that were already stolen before the patch was applied. Organisations that assume a successful update closes the incident are, in many cases, simply leaving a forged key in place while believing the door has been locked.

This is not an isolated flaw sitting on its own. CVE-2026-50522 is the third SharePoint Server vulnerability to see active exploitation this month, following CVE-2026-56164, rated a comparatively modest 5.3, and CVE-2026-58644, which like this newest flaw carries a 9.8 severity rating and was weaponised as a zero day before Microsoft's fix shipped.

The US Cybersecurity and Infrastructure Security Agency has gone further still, warning that threat actors are actively exploiting a set of four separate SharePoint Server vulnerabilities in combination, adding CVE-2026-32201 and CVE-2026-45659 to the list alongside the two more recent entries. CISA describes the pattern consistently across all four: establishing remote code execution, then moving into post exploitation activity focused specifically on stealing IIS machine keys and performing further deserialization based persistence techniques. Every supported on-premises SharePoint version is affected, spanning Subscription Edition, 2019, and 2016 releases alike.

There is a structural reason SharePoint keeps generating this particular pattern of vulnerability. On-premises SharePoint deployments are enormous, deeply customised pieces of enterprise software that many organisations have run largely unchanged for years, frequently holding a mixture of confidential documents, internal collaboration data, and identity integration points that make them an unusually rich target once an attacker gets a foothold.

"Layer in the fact that deserialization vulnerabilities are notoriously difficult to fully eliminate from large legacy codebases, since they tend to reappear in new code paths even after a specific instance is patched, and it becomes clearer why the same product keeps resurfacing with a similar exploitation signature month after month, even as Microsoft ships fixes. This is the same legacy systems gap regulators have already flagged as a common compliance failure point, since organisations often carry known weaknesses in older, unpatched or under-monitored systems well past the point where a security review should have caught them."

For enterprise security teams running on-premises SharePoint anywhere in the GCC, the practical response here has to go beyond simply applying the July patch. Any organisation that had an internet facing or otherwise exposed SharePoint instance during the exploitation window should assume machine keys may already be compromised and should rotate them directly rather than relying on the patch alone to resolve exposure.

That rotation needs to happen at the ASP.NET machine key level, not just through a password reset, since the stolen material lets an attacker forge valid session and authentication tokens independent of any single user's credentials. Security teams should also review authentication logs for anomalous Site Owner level activity predating detection, since the exploitation chain requires that access as a starting point, and any account showing unexplained privilege at that level deserves closer scrutiny regardless of whether it maps to a known compromise.

Given how consistently SharePoint has generated critical, actively exploited vulnerabilities this year, organisations with a realistic option to migrate sensitive workloads toward more actively maintained cloud-hosted alternatives should weigh that migration cost against the recurring cost of responding to on-premises SharePoint incidents on what is becoming close to a monthly cadence.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Threat IntelligenceActively Exploited VulnerabilitiesEnterprise Infrastructure Security