Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [...]

Threat actors are actively exploiting a critical remote code execution (RCE) vulnerability in Microsoft SharePoint, designated CVE-2026-50522, to compromise on-premise deployments. The flaw, a deserialization-of-untrusted-data issue, allows unauthenticated attackers to execute arbitrary code over a network.
Microsoft released patches for CVE-2026-50522 in its July security updates. While the company did not initially mark the vulnerability as actively exploited, it did note an increased likelihood of exploitation. Cybersecurity firm watchTowr confirmed active exploitation shortly after a proof-of-concept (PoC) exploit became publicly available.
On July 20, watchTowr identified a valid PoC for CVE-2026-50522. Within hours, their global honeypot network, Attacker Eye, recorded successful exploitation attempts utilizing this PoC. The firm observed attackers stealing machine keys, a tactic that allows them to maintain persistent access to compromised systems even after the underlying SharePoint servers are patched.
Earlier, on July 17, the threat intelligence company Defused had detected an "undocumented SharePoint deserialization vector" being used in attacks. At that time, Defused could not definitively link the activity to a specific vulnerability. However, the company later stated that these attacks were likely driven by exploitation of CVE-2026-50522.
A PowerShell-based PoC exploit for CVE-2026-50522, developed by security researcher Janggggg, is publicly available on GitHub. This PoC attempts to achieve RCE by delivering a malicious .NET BinaryFormatter payload. The payload is crafted as a cookie within a forged SecurityContextToken, which is then posted to SharePoint's /_trust/default.aspx endpoint as part of a WS-Federation sign-in response. If a vulnerable deserialization path processes this token, the payload executes arbitrary code on the SharePoint server.
Janggggg published the PoC on the same day watchTowr began detecting exploitation attempts. However, it remains unconfirmed whether the observed attacks directly utilized this specific publicly available exploit.
While applying the latest SharePoint security updates will mitigate the vulnerability, watchTowr advises organizations to take additional precautions. Specifically, defenders should rotate credentials on any assets that may have been exposed to potential compromise, given the attackers' objective of stealing machine keys for persistent access.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]