Advisory
23 July 2026
Background
CVSSv3 Score: Base 9.8 Critical
A critical security vulnerability (CVSS 3.1 score: 9.8) has been identified in on-premises deployments of Microsoft SharePoint Server. This vulnerability allows unauthenticated users to run malicious code on SharePoint servers to steal IIS machine keys which can be used to bypass all login screens and masquerade as administrators. This flaw is caused by the deserialization of untrusted data within SharePoint's core processing components, allowing a remote, unauthenticated attacker to execute malicious code on vulnerable systems.
Threat actors are actively exploiting this vulnerability to steal IIS machine keys, granting them the ability to bypass all login screens, forge administrative access, and maintain long-term persistence. Because stolen machine keys may allow attackers to retain access even after a system is patched, remediation requires immediate installation of Microsoft’s July 2026 updates and a manual rotation of the servers’ IIS machine key.
Impact
- Allows unauthorized attackers to execute code over a network
- Enables the deployment web shells for persistent access
- Allows access to or modification of sensitive SharePoint documents
- Enables the theft of credentials or authentication-related
- Move laterally within the organisation’s network
- May disrupt SharePoint services
Affected Products
| Product | Affected Versions |
|---|---|
| Microsoft Sharepoint Server Subscription Edition | Versions prior to 16.0.19725.20434 |
| Microsoft Sharepoint Server 2019 | Versions prior to 16.0.10417.20175 |
| Microsoft Sharepoint Server 2016 | Versions prior to 16.0.5561.1001 |
Recommendations
- Apply the latest security updates provided by Microsoft to affected SharePoint Server systems as soon as possible.
- Identify and patch all affected SharePoint servers within the organization’s environment.
- Conduct threat hunting and a compromise assessment to identify possible signs of exploitation.
- Manually Rotate the IIS Machine Keys
- Rotate credentials and sensitive secrets if there is any indication that the affected SharePoint server may have been compromised.
- Restrict external access to on-premises SharePoint servers by allowing access only from trusted networks or through secure remote access solutions.
- Monitor SharePoint and system logs for suspicious activity, including unusual login attempts, abnormal requests, or unauthorized changes.
- Review and strengthen access controls by enforcing the principle of least privilege and removing unnecessary administrative access.
- Maintain regular backups of critical SharePoint data and verify that recovery procedures are available.
References
- https://msrc.microsoft.com/update-guide/
- https://thehackernews.com/2026/07/critical-sharepoint-rce-cve-2026-50522.html
- https://nvd.nist.gov/vuln/detail/CVE-2026-50522
- https://www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2026-50522