A critical Remote Code Execution (RCE) vulnerability in on-premises Microsoft SharePoint is being actively exploited to steal cryptographic machineKey entries. The campaign, targeting CVE-2026-50522, establishes persistent backdoor access that remains operational even after security patches are applied.
As reported by BleepingComputer, the attack unfolds in two stages. Adversaries first leverage the RCE flaw to gain code execution on a vulnerable server. Their primary goal is not immediate disruption, but the exfiltration of machineKey entries from the server's configuration. These .NET framework keys are used to encrypt and validate authentication cookies and ViewState payloads.
With these stolen keys, attackers can forge valid cryptographic material, impersonate users, and maintain a persistent foothold. This means patching the initial vulnerability closes only the entry point, leaving the backdoor open.
For organizations running their own SharePoint farms, this creates a critical, two-step remediation imperative. The immediate priority is to apply Microsoft's security patch to halt active exploitation. However, a comprehensive rotation of all machineKey entries across the entire SharePoint farm—and any other applications that trusted those keys—is essential to revoke persistent access. A thorough security audit for signs of compromise is also strongly advised.
The threat is explicitly confined to on-premises SharePoint Server installations; cloud-based SharePoint Online is unaffected. This clear delineation underscores the distinct security responsibilities inherent in managing local infrastructure.
For IT and security teams, the incident highlights a strategic shift in attacker objectives toward long-term, stealthy network control. Effective defense now requires managing cryptographic secrets with the same rigor as domain credentials. Organizations should inventory all systems sharing SharePoint machineKeys, develop plans for rapid key rotation, and enhance monitoring for anomalous cryptographic operations and ViewState usage. Relying solely on vulnerability patching is no longer sufficient to ensure system integrity.
Microsoft SharePoint內部部署版本的一個嚴重遠端代碼執行(RCE)漏洞正遭積極利用,用以竊取加密的machineKey條目。此攻擊行動針對漏洞CVE-2026-50522,建立了持久性後門訪問權限,即使套用安全補丁後仍能持續運作。
據BleepingComputer報道,該攻擊分兩階段進行。攻擊者首先利用RCE漏洞在受影響的伺服器上取得代碼執行權限。其主要目標並非立即造成系統中斷,而是從伺服器配置中外傳machineKey條目。這些.NET框架密鑰用於加密及驗證「驗證 Cookie」以及ViewState負載。
持有這些被竊取的密鑰,攻擊者即可偽造有效的加密材料、冒充用戶,並維持持久性據點。這意味著修補初始漏洞只是關閉了入侵點,後門依然敞開。
對於營運自身SharePoint伺服器群組的企業而言,這帶來了關鍵的兩階段補救要求。當務之急是套用Microsoft的安全補丁以遏制當前漏洞利用。然而,為撤銷持久性訪問權限,必須全面輪換整個SharePoint伺服器群組——以及任何其他信任這些密鑰的應用程式——的所有machineKey條目。同時強烈建議進行徹底的安全審計,排查入侵跡象。
該威脅明確僅限於內部部署版SharePoint Server安裝環境;雲端版SharePoint Online並不受影響。此清晰界線突顯了管理本地基礎設施所固有的差異化安全責任。
對IT及安全團隊而言,此事件凸顯攻擊者目標正向長期、隱蔽的網絡控制策略轉移。現今有效的防禦措施,要求以管理網域憑證的同等嚴謹度來管理加密機密。企業應清點所有共享SharePoint machineKeys的系統,制定快速密鑰輪換計劃,並加強監控異常加密操作及ViewState使用行為。僅依賴漏洞補丁已不足以確保系統完整性。
