Hackers exploit Microsoft SharePoint flaw to get long-term access

 

Hackers exploit Microsoft SharePoint flaw to get long-term access

Hackers are actively exploiting a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-50522, to steal machine keys and keep access to compromised servers even after security patches are installed.

The flaw is a deserialization vulnerability that allows attackers to remotely execute code on vulnerable on-premises SharePoint servers without authentication. Microsoft fixed the issue in its July security updates and warned that it was likely to be exploited.

Security researchers at watchTowr said attackers began targeting vulnerable systems shortly after a proof-of-concept (PoC) exploit was released publicly. The attackers are stealing machine keys, which can be used to create valid authentication tokens, impersonate users, and access SharePoint sites and documents with the same permissions as those users.

The US Cybersecurity and Infrastructure Security Agency (CISA) has since warned that threat actors are actively exploiting multiple SharePoint Server vulnerabilities, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, to gain unauthorized access to on-premises SharePoint servers.

Threat intelligence company Defused also reported seeing attacks using what it described as an undocumented SharePoint deserialization method as early as July 17, before the activity was linked to CVE-2026-50522.

Organizations running on-premises SharePoint servers are urged to install Microsoft's latest security updates as soon as possible and check systems for signs of compromise.


Back to the list