"Attackers are pulling SharePoint machine keys via a single request," watchTowr warned, describing the technique adversaries are using to convert a single exploit into persistent access.
CVE-2026-50522: what Microsoft says
Microsoft patched CVE-2026-50522 as part of its July 2026 Patch Tuesday. The company classified the flaw as a critical deserialization of untrusted data in Microsoft Office SharePoint with a CVSS score of 9.8. Microsoft credited DEVCORE researcher "splitline" with discovering and reporting the vulnerability.
In its advisory, Microsoft described the exploitation scenario bluntly: "In a network-based attack, an attacker authenticated as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server." The vendor further characterized the attack vector as Network (AV:N) and the attack complexity as Low (AC:L), and it assigned an exploitability assessment of "Exploitation More Likely."
Active exploitation after public proof-of-concept, per watchTowr
Security firm watchTowr reported that it detected active exploitation of CVE-2026-50522 against on-premises SharePoint deployments following publication of a public proof-of-concept (PoC) exploit. According to watchTowr, attackers are using the PoC to steal SharePoint machine keys, a technique that can preserve access long after the initial compromise.
WatchTowr warned that simple patching may not be sufficient to remove that access: "Patching is not enough; defenders should rotate credentials on any assets that may have been exposed." The vendor said attackers are able to pull those machine keys via a single request, turning one remotely exploitable fault into a persistent foothold.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildRelated SharePoint flaws and CISA's advisory
CVE-2026-50522 is the third SharePoint Server vulnerability observed under active exploitation in July 2026, following CVE-2026-56164 (CVSS 5.3) and CVE-2026-58644 (CVSS 9.8). The Hacker News reported that the earlier two were weaponized as zero-days prior to their fixes in July 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are exploiting multiple SharePoint Server vulnerabilities — specifically naming CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644 — to gain unauthorized access to on-premises instances. CISA said these issues affect all supported on-premises SharePoint Server versions (Subscription Edition, 2019, and 2016) and involve establishing remote code execution and post-exploitation activities, "such as stealing Internet Information Services (IIS) machine keys and performing deserialization techniques, to gain persistence and deploy malware."
What this means for on-premises SharePoint owners, security teams, and CISA
- On-premises SharePoint owners: These organizations are the immediate target. The published PoC and reported machine-key theft mean administrators should not assume patching alone ends exposure; watchTowr explicitly advised rotating credentials on any assets that may have been exposed.
- Security teams and defenders: With Microsoft labeling CVE-2026-50522 as remotely exploitable with low complexity and an "Exploitation More Likely" assessment, defenders should search for evidence of machine-key exfiltration and focus post-patch efforts on credential rotation and integrity checks for IIS and SharePoint artifacts.
- CISA and agencies: CISA has already issued a broad warning naming specific SharePoint CVEs and describing post-exploitation techniques. That advisory frames these incidents as a multi-vulnerability campaign against supported on-premises SharePoint versions and underlines the cross-cutting nature of the threat.
Closing observation
The pattern is clear in the available record: a sequence of high-severity SharePoint flaws has moved from discovery to public PoC to active exploitation within weeks. Microsoft has published technical guidance and credited the researcher who reported CVE-2026-50522; watchTowr and CISA have moved to warn operators that exploitation can yield machine keys and persistent access. For operators who run on-premises SharePoint — Subscription Edition, 2019, or 2016 — the practical imperative in the face of an "Exploitation More Likely" assessment is twofold: apply the bulletin fixes and assume that patching alone may not remove existing access without rotating exposed credentials.




