← Back to Tech & Science

Critical SharePoint Vulnerability Under Active Exploitation Following Public PoC Release

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

LONDON (July 21, 2026) — Threat actors are actively exploiting a critical vulnerability in Microsoft's on-premises SharePoint Server to execute remote code and steal machine keys for persistent access. The flaw, identified as CVE-2026-50522, has triggered urgent security alerts following the release of a public proof-of-concept exploit earlier today.

The attack vector allows unauthenticated attackers to compromise servers without prior credentials. Once inside, malicious actors can extract machine keys, which serve as cryptographic secrets used by SharePoint for encryption and authentication processes. Possession of these keys enables threat groups to maintain long-term access even if the underlying software vulnerability is patched or server configurations are altered.

Security researchers confirmed that exploitation attempts began immediately after a proof-of-concept code snippet detailing the flaw was published on public repositories at approximately 15:09 UTC. The rapid transition from disclosure to active weaponization marks this incident as one of the most aggressive campaigns targeting enterprise collaboration infrastructure in recent months.

Microsoft has acknowledged the severity of CVE-2026-50522, classifying it as critical due to its potential for remote code execution and data exfiltration. The company stated that organizations running on-premises SharePoint Server versions 2019 through 2022 are at immediate risk if they have not applied the latest security updates released in a non-public advisory earlier this week.

The vulnerability stems from an improper validation of user input within specific web application components. When exploited, the flaw bypasses standard authentication checks, granting attackers administrative-level privileges over the affected server instance. This access point is particularly dangerous for organizations relying on SharePoint to host sensitive internal documents and intellectual property.

Network traffic analysis indicates that scanning activity targeting vulnerable ports has surged globally since midday. Several major financial institutions and government agencies have reportedly blocked inbound connections from known malicious IP addresses associated with the campaign, though no confirmed breaches of specific high-profile entities have been publicly disclosed as of this afternoon.

Experts warn that the availability of a working exploit code lowers the technical barrier for entry, allowing less sophisticated actors to launch attacks alongside organized cybercrime groups. The primary objective appears to be establishing persistent backdoors rather than immediate ransomware deployment or data destruction, suggesting a focus on long-term espionage or future leverage.

Questions remain regarding whether any state-sponsored entities are leveraging the vulnerability in coordination with criminal syndicates. Additionally, it is unclear how many organizations have successfully deployed mitigations before active exploitation began. Microsoft has urged administrators to apply patches immediately and monitor for unauthorized changes to machine key configurations until all systems are updated.

Discussion

0 / 2000