"Attackers are pulling SharePoint machine keys via a single request," watchTowr warned, describing the technique adversaries are using to convert a single exploit into persistent access.
CVE-2026-50522: what Microsoft says
Microsoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday. The company classified the flaw as a critical deserialization of untrusted data in Microsoft Office SharePoint with a CVSS score of 9.8. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the vulnerability.
In its advisory, Microsoft described the exploitation scenario bluntly: "In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server." The vendor further characterized the attack vector as Network (AV:N) and the attack complexity as Low (AC:L), and it assigned an exploitability assessment of "Exploitation More Likely."
Active exploitation after public proof-of-concept, per watchTowr
Security firm watchTowr reported that it detected active exploitation of CVE-2026-50522 against on-premises SharePoint deployments following publication of a public proof-of-concept (PoC) exploit. According to watchTowr, attackers are using the PoC to steal SharePoint machine keys, a technique that can preserve access long after the initial compromise.
WatchTowr warned that simple patching may not be sufficient to remove that access: "Patching is not enough; defenders should rotate credentials on any assets that may have been exposed." The vendor said attackers are able to pull those machine keys via a single request, turning one remotely exploitable fault into a persistent foothold.
Related SharePoint flaws and CISA's advisory
CVE-2026-50522 is the third SharePoint Server vulnerability observed under active exploitation in July 2026, following CVE-2026-56164 (CVSS 5.3) and CVE-2026-58644 (CVSS 9.8). The Hacker News reported that the earlier two were weaponized as zero-days prior to their fixes in July 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are exploiting multiple SharePoint Server vulnerabilities — specifically naming CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644 — to gain unauthorized access to on-premises instances. CISA said these issues affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution and post-exploitation activities, "such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware."
What this means for on-premises SharePoint owners, security teams, and CISA
- On-premises SharePoint owners: These organizations are the immediate target. The published PoC and reported machine-key theft mean administrators should not assume patching alone ends exposure; watchTowr explicitly advised rotating credentials on any assets that may have been exposed.
- Security teams and defenders: With Microsoft labeling CVE-2026-50522 as remotely exploitable with low complexity and an "Exploitation More Likely" assessment, defenders should search for evidence of machine-key exfiltration and focus post-patch efforts on credential rotation and integrity checks for IIS and SharePoint artifacts.
- CISA and agencies: CISA has already issued a broad warning naming specific SharePoint CVEs and describing post-exploitation techniques. That advisory frames these incidents as a multi-vulnerability campaign against supported on-premises SharePoint versions and underlines the cross-cutting nature of the threat.
Closing observation
The pattern is clear in the available record: a sequence of high-severity SharePoint flaws has moved from discovery to public PoC to active exploitation within weeks. Microsoft has published technical guidance and credited the researcher who reported CVE-2026-50522; watchTowr and CISA have moved to warn operators that exploitation can yield machine keys and persistent access. For operators who run on-premises SharePoint — Subscription Edition, 2019, or 2016 — the practical imperative in the face of an "Exploitation More Likely" assessment is twofold: apply the bulletin fixes and assume that patching alone may not remove existing access without rotating exposed credentials.




