Code Defence Cyber security

Critical Microsoft SharePoint RCE flaw CVE-2026-50522 exploited in the wild to exfiltrate machine keys

A critical deserialization of untrusted data vulnerability residing within an enterprise document aggregation and collaboration platform is undergoing active wild exploitation. The flaw allows unauthenticated remote network actors to execute arbitrary code streams and extract core application secret keys directly over network connections.

Tracked as CVE-2026-50522 with a CVSS score of 9.8, the defect impacts on-premises Microsoft SharePoint Server installations. Threat monitoring telemetry confirms that adversaries are leveraging public proof of concept code blocks to issue unauthenticated requests against sign-in endpoints. By executing the payload, threat actors capture IIS machine keys, allowing them to forge persistent session tokens and maintain administrative access across the collaboration farm even after binary security patches are installed.

Exfiltrating IIS machine keys from a centralized collaboration server creates severe long-term security hazards. Because compromised machine keys grant attackers the ability to sign and decrypt viewstate parameters independently, an adversary retains persistent administrative impersonation capabilities across adjacent subnets, neutralizing traditional identity boundary controls.

– Apply the latest security updates provided by Microsoft across all on-premises SharePoint deployments immediately.

– Execute mandatory key rotation procedures for all IIS machine keys across exposed SharePoint farms to invalidate intercepted tokens.

– Restrict network access to SharePoint administrative endpoints by placing instances behind pre-authenticated zero trust reverse proxies.

– Monitor IIS web logs for anomalous single-request GET or POST parameters carrying unauthenticated deserialization headers.

Enterprise document architecture defense demands immediate patch installation paired with complete cryptographic credential rotation to guarantee that compromised machine keys cannot maintain persistent backdoor channels. #CodeDefence #Microsoft #SharePoint #RCE #MachineKeys #CISA #KEV
/

Scroll to Top