Home/News/SharePoint RCE Flaw Exploited to Steal Machine Keys
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

SharePoint RCE Flaw Exploited to Steal Machine Keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. This remote code execution (RCE) flaw allows attackers to compromise SharePoint servers and potentially gain unauthorized access to sensitive data and systems. The exploit targets the server-side request forgery (SSRF) component of the vulnerability, enabling attackers to manipulate requests and exfiltrate machine keys.

Security researchers at Mandiant first observed the exploitation of CVE-2026-50522 in late 2023. The attackers are leveraging this vulnerability to establish a foothold within organizations' networks, allowing them to move laterally and escalate privileges. The stolen machine keys can be used to bypass authentication mechanisms and impersonate legitimate users or services, significantly increasing the risk of further compromise. This persistent access is a major concern as it circumvents traditional patching strategies.

Microsoft released a security advisory and patches for CVE-2026-50522 in January 2024. However, the ongoing exploitation indicates that many organizations have not yet applied these critical updates. The attackers are reportedly using custom tools and techniques to exploit the vulnerability, making detection more challenging. The impact of this vulnerability extends beyond SharePoint itself, as compromised machine keys can unlock access to other connected systems and cloud services within an organization's infrastructure.

Mandiant's analysis suggests that the threat actors are sophisticated and have been actively refining their exploitation methods. The company recommends that all organizations using Microsoft SharePoint apply the latest security updates immediately and conduct thorough investigations for any signs of compromise. Implementing robust network segmentation and monitoring for unusual outbound traffic can also help mitigate the risks associated with this type of persistent threat.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next