A serious vulnerability has been identified in Microsoft SharePoint Server that allows attackers to take control of a server with comparatively little effort.
A corresponding attack code has been publicly available for a few days, and security researchers are already recording active waves of attacks.
Please note: Retrofitting the update alone is not sufficient in this case – affected companies should act at short notice.
What happened?
The vulnerability bears the identifier CVE-2026-50522. They allow attackers to remotely execute malicious code on a SharePoint server. In the worst case, a single prepared request via the Internet is sufficient, without any user account or login.
Microsoft already closed the vulnerability on July 14, 2026 with a security update. However, since July 20, a finished attack code has been publicly available, and security researchers have been observing active attack attempts on unpatched servers since then.
Particularly important: The attackers try to capture so-called machine keys, digital keys with which they can gain permanent access to the server even after a later update. Installing the update alone is therefore not enough to secure servers that have already been affected.
How does the attack work?
The attack is specifically aimed at the login function of SharePoint servers that are accessible from the Internet. In this case, the attackers send a specially crafted request to the server, which the server processes incorrectly, whereby injected code is executed. If this first step is successful, the attackers grab the server’s machine keys in a second step and thus secure permanent access that will survive a later update. Since no user login is required for this process, all unpatched servers accessible from the Internet are at risk.
What is affected?
The vulnerability affects only self-operated (“on-premises”) SharePoint servers:
SharePoint Online (the cloud variant within Microsoft 365) is not affected.
How can I protect myself?
We recommend that companies using the affected versions take the following measures:
Conclusion
CVE-2026-50522 is an example of how quickly a closed vulnerability can become an acute risk again: An available patch only protects if it is installed across the board – and even then, the risk remains that access keys have already been stolen before the update.
A clear priority is therefore important, especially for SMEs without a large in-house IT security department: install updates, rotate machine keys, restrict external access and have their own systems checked for anomalies. Those who implement these steps now will not only close the current gap, but also reduce the risk of being affected by follow-up attacks in the coming weeks – SharePoint servers are currently increasingly being targeted by attackers.
If you have any questions about the implementation, please do not hesitate to contact us.
Your Perseus Team
Do you want to stay informed about current threats and security vulnerabilities?
Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.
Sources & Further Information