← volver al portal

Critical SharePoint Vulnerability Actively Exploited to Steal Authentication Keys

Cybercriminals are actively exploiting CVE-2026-50522, a critical remote code execution flaw in Microsoft SharePoint, to steal machine keys that enable…

IT teams must urgently apply Microsoft's July security patches to all SharePoint servers, though compromised machine keys will enable authentication bypass even post-patch. Organizations should audit access logs from July 17 onward, monitor elevated privilege access attempts, regenerate machine keys and authentication tokens on potentially compromised systems, and block access to the '/_trust/default.aspx' endpoint if not essential.