Home / Jul 22, 2026 / Story
0
#1 BleepingComputer general July 21, 2026 at 20:06 UTC

Critical SharePoint RCE flaw exploited to steal machine keys

By Bill Toulas

AI Summary

CVE-2026-50522, a critical (CVSS 9.8) deserialization RCE flaw in Microsoft SharePoint Server, is being actively exploited to steal machine keys — allowing attackers to maintain persistent access even after patching. The technique is particularly dangerous because machine key theft enables forging ViewState tokens and achieving RCE on patched servers, meaning remediation requires key rotation in addition to patching.

Relevance score: 92.0/100

# More from July 22