In the event of a current attack pattern or a security vulnerability, Perseus sends out warning emails containing specific countermeasures.
24.07.2026

Critical warning to SharePoint users: Vulnerability is being actively attacked

A serious vulnerability has been identified in Microsoft SharePoint Server that allows attackers to take control of a server with comparatively little effort.

A corresponding attack code has been publicly available for a few days, and security researchers are already recording active waves of attacks.

Please note: Retrofitting the update alone is not sufficient in this case – affected companies should act at short notice.

What happened?

The vulnerability bears the identifier CVE-2026-50522. They allow attackers to remotely execute malicious code on a SharePoint server. In the worst case, a single prepared request via the Internet is sufficient, without any user account or login.

Microsoft already closed the vulnerability on July 14, 2026 with a security update. However, since July 20, a finished attack code has been publicly available, and security researchers have been observing active attack attempts on unpatched servers since then.

Particularly important: The attackers try to capture so-called machine keys, digital keys with which they can gain permanent access to the server even after a later update. Installing the update alone is therefore not enough to secure servers that have already been affected.

How does the attack work?

The attack is specifically aimed at the login function of SharePoint servers that are accessible from the Internet. In this case, the attackers send a specially crafted request to the server, which the server processes incorrectly, whereby injected code is executed. If this first step is successful, the attackers grab the server’s machine keys in a second step and thus secure permanent access that will survive a later update. Since no user login is required for this process, all unpatched servers accessible from the Internet are at risk.

What is affected?

The vulnerability affects only self-operated (“on-premises”) SharePoint servers:

  • SharePoint Enterprise Server 2016
  • SharePoint Server 2019
  • SharePoint Server Subscription Edition

SharePoint Online (the cloud variant within Microsoft 365) is not affected.

How can I protect myself?

We recommend that companies using the affected versions take the following measures:

  1. Install the security update. Make sure that the July 14, 2026 update is installed on all servers in your SharePoint environments, not just the server that is accessible from the outside. If you operate several SharePoint servers in a network (“farm”), each one must be updated, otherwise the gap will remain over the unpatched servers.
  2. Renew access keys (machine keys). These keys are used by SharePoint to secure sessions. If they were already stolen before patching, they remain valid after the update and continue to allow access. Your IT service provider or department can regenerate and distribute these keys via SharePoint Central Administration or PowerShell. If in doubt, ask specifically whether this step has already been taken – it is easily overlooked when patching.
  3. Restrict access from the outside. As long as the update has not yet been installed on all servers, access to the SharePoint login pages should be restricted as much as possible from the outside, for example via the firewall or a VPN, so that only known, trusted addresses can access.
  4. Have abnormalities checked. Have your IT service provider or IT department check the access logs of the SharePoint servers for the period from July 17, 2026. Pay particular attention to: an unusually large number of or unusually shaped login requests, login attempts from unknown or foreign IP addresses outside of normal usage hours, as well as newly created user accounts or administrative access that no one in the team has initiated. It is also useful to compare it with the manufacturer’s instructions for known attack characteristics (indicators of compromise) by an IT security service provider if you yourself are unsure what exactly to look for.

Conclusion

CVE-2026-50522 is an example of how quickly a closed vulnerability can become an acute risk again: An available patch only protects if it is installed across the board – and even then, the risk remains that access keys have already been stolen before the update.

A clear priority is therefore important, especially for SMEs without a large in-house IT security department: install updates, rotate machine keys, restrict external access and have their own systems checked for anomalies. Those who implement these steps now will not only close the current gap, but also reduce the risk of being affected by follow-up attacks in the coming weeks – SharePoint servers are currently increasingly being targeted by attackers.

If you have any questions about the implementation, please do not hesitate to contact us.

Your Perseus Team

Do you want to stay informed about current threats and security vulnerabilities?

Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.

Sources & Further Information