Executive Summary
A newly discovered critical vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is being actively exploited by sophisticated threat actors. This vulnerability, which enables remote code execution (RCE) via deserialization of untrusted data, affects all supported on-premises versions of Microsoft SharePoint Server. Attackers are leveraging this flaw to gain unauthorized access, steal sensitive credentials, deploy webshells, and establish persistent footholds within enterprise environments. The exploitation is low in complexity, can be automated, and has already resulted in significant breaches, including ransomware deployments and data exfiltration. Immediate action is required to mitigate risk, as both state-sponsored advanced persistent threat (APT) groups and financially motivated cybercriminals are targeting vulnerable organizations globally.
Threat Actor Profile
Recent campaigns exploiting CVE-2026-50522 have been attributed to a mix of state-linked and criminal actors. Notably, Chinese APT groups such as Linen Typhoon and Violet Typhoon have been observed leveraging this exploit for espionage and intellectual property theft, targeting government, defense, and critical infrastructure sectors. Additionally, ransomware operators, including those associated with the Warlock and Lockbit families, have exploited the vulnerability to deploy ransomware and extort organizations. These actors demonstrate advanced capabilities, including the use of custom webshells, credential theft, lateral movement tools like Impacket and PsExec, and sophisticated persistence mechanisms. Their operations are characterized by rapid exploitation following public disclosure, automation of attack chains, and targeting of organizations with exposed or unpatched SharePoint servers.
Technical Analysis of Malware/TTPs
The exploitation of CVE-2026-50522 involves sending specially crafted HTTP POST requests to vulnerable SharePoint endpoints, particularly the ToolPane.aspx interface. Successful exploitation allows attackers to execute arbitrary code in the context of the SharePoint application pool, often resulting in the deployment of webshells such as spinstall0.aspx and spinstall1.aspx. These webshells provide remote access and command execution capabilities.
Post-exploitation, attackers frequently extract machineKey values from the web.config file, enabling them to forge authentication tokens and maintain persistent access. Malicious DLLs, such as IIS_Server_dll.dll, are deployed to facilitate further exploitation and credential theft. Attackers utilize PowerShell and cmd.exe for reconnaissance, privilege escalation, and lateral movement. Tools like Impacket and PsExec are employed to move laterally within the network, while scheduled tasks and IIS configuration modifications ensure persistence.
Ransomware deployment, particularly by the Warlock group, has been observed through the modification of Group Policy Objects (GPOs), allowing attackers to encrypt files across the compromised environment. The attack chain is further enhanced by the use of custom command-and-control (C2) domains, such as update.updatemicfosoft.com and msupdate.updatemicfosoft.com, and the exfiltration of sensitive data prior to ransomware activation.
Exploitation in the Wild
Active exploitation of CVE-2026-50522 has been confirmed by multiple security vendors, including Microsoft, CISA, and independent researchers such as watchTowr and Defused. Public exploit code is available, lowering the barrier to entry for less sophisticated attackers. Campaigns have targeted hundreds of organizations worldwide, with a focus on entities running on-premises Microsoft SharePoint Server 2016, 2019, and Subscription Edition.
Notable incidents include the compromise of US federal agencies, critical infrastructure providers, and private sector organizations. Attackers have demonstrated the ability to automate exploitation, rapidly pivot within compromised environments, and deploy ransomware at scale. The ToolShell campaign of 2025, which shares TTPs with current activity, resulted in widespread data breaches and operational disruptions.
Indicators of compromise (IOCs) associated with these attacks include the presence of webshells in SharePoint directories, unauthorized modifications to web.config and applicationHost.config, suspicious outbound network connections, and anomalous authentication events involving SharePoint service accounts.
Victimology and Targeting
The primary targets of these exploitation campaigns are organizations operating on-premises Microsoft SharePoint Server instances that are exposed to the internet and have not applied the latest security patches. Sectors most affected include government, defense, critical infrastructure, healthcare, education, and large enterprises with complex IT environments.
Geographically, while US-based organizations have been heavily targeted, the global nature of Microsoft SharePoint deployments means that entities in Europe, Asia-Pacific, and the Middle East are also at significant risk. The opportunistic nature of the attacks, combined with the availability of automated exploit tools, has led to indiscriminate scanning and exploitation attempts across the internet.
Victims have reported a range of impacts, from data theft and credential compromise to full-scale ransomware incidents resulting in operational downtime and financial losses. The theft of machineKey values and subsequent token forgery has enabled attackers to bypass authentication controls and escalate privileges within affected environments.
Mitigation and Countermeasures
To mitigate the risk posed by CVE-2026-50522 and related vulnerabilities, organizations must take immediate and comprehensive action. The following countermeasures are recommended:
Apply all available Microsoft SharePoint security updates released in July 2026 or later. Ensure that all on-premises SharePoint servers, including 2016, 2019, and Subscription Edition, are fully patched.
Rotate ASP.NET machine keys and all credentials associated with SharePoint service accounts. After patching, restart IIS using iisreset.exe to ensure that new keys are in effect.
Conduct a thorough audit of SharePoint server directories for unauthorized webshells (e.g., spinstall0.aspx, spinstall1.aspx) and malicious DLLs. Remove any suspicious files and restore configurations from known-good backups.
Review and monitor authentication logs for anomalous activity, including unexpected use of service accounts and failed login attempts. Enable advanced logging and integrate with a Security Information and Event Management (SIEM) solution for real-time alerting.
Restrict external access to SharePoint administrative interfaces and implement network segmentation to limit lateral movement opportunities. Where possible, place SharePoint servers behind a web application firewall (WAF) with rules to detect and block exploit patterns.
Enable and configure Antimalware Scan Interface (AMSI) integration in SharePoint to detect and block malicious scripts and payloads. Deploy endpoint detection and response (EDR) solutions on all SharePoint servers.
Educate IT and security staff on the latest TTPs associated with SharePoint exploitation, including the use of webshells, credential theft, and ransomware deployment. Conduct regular incident response exercises to ensure preparedness.
Monitor for IOCs, including connections to known malicious IPs (65.38.121.198, 104.238.159.149, 134.199.202.205, 188.130.206.168, 131.226.2.6) and C2 domains (update.updatemicfosoft.com, msupdate.updatemicfosoft.com).
Disconnect or decommission any end-of-life or unsupported SharePoint servers that cannot be adequately secured.
References
Cybersecurity Dive: Microsoft SharePoint under attack via new exploit (CVE-2026-50522), CISA Alert: Exploitation of SharePoint Vulnerabilities, Microsoft Security Blog: Disrupting active exploitation of on-premises SharePoint vulnerabilities, CyberScoop: Microsoft SharePoint attacks ensnare 400 victims, including US agencies, CNBC: Microsoft: Chinese hacking groups were part of SharePoint attacks, ShadowServer Foundation: SharePoint exposure statistics, watchTowr LinkedIn post on CVE-2026-50522 exploitation, MITRE ATT&CK T1190, CVE-2026-50522 NVD Entry.
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to identify, assess, and mitigate cyber risks across their digital supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively defend against emerging threats and ensure compliance with industry standards. For more information about how Rescana can help strengthen your organization’s cyber resilience, please visit https://www.rescana.com.
We are happy to answer questions at info@rescana.com.



