Attackers are exploiting the CVE-2026-50522 deserialization vulnerability in Microsoft SharePoint to steal machine keys and maintain persistent access to systems even after the patch has been applied. The vulnerability enables remote code execution without authentication and was addressed in July's security updates.
Security firm watchTowr detected attacks exploiting this vulnerability within hours of the public release of proof-of-concept (PoC) code, using a global honeypot network. Attackers are using specially crafted .NET BinaryFormatter payloads to gain access to SharePoint servers; when these payloads are sent to the WS-Federation authentication endpoint, they trigger arbitrary code execution.
Other security organizations, such as Defused, also observed similar attacks starting on July 17, although the full identity of the vulnerability was not known at the time. Security experts emphasize that systems exposed to this flaw must have their credentials reset even after applying the patch.
