SharePoint CVE-2026-50522: Why Patching Alone Won't Evict the Attacker

Microsoft patched CVE-2026-50522 (CVSS 9.8) on 14 July 2026, but watchTowr observed ASP.NET machine-key theft that persists post-patch, and CISA added it to KEV on 22 July with a 25 July deadline. A six-point managed-patching, rotation and assume-breach playbook for on-premises SharePoint.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai

SharePoint CVE-2026-50522: Why Patching Alone Won't Evict the Attacker

Microsoft patched CVE-2026-50522 (CVSS 9.8) on 14 July 2026, but watchTowr observed ASP.NET machine-key theft that persists post-patch, and CISA added it to KEV on 22 July with a 25 July deadline. A six-point managed-patching, rotation and assume-breach playbook for on-premises SharePoint.

Häufig gestellte Fragen

What did Microsoft patch on 14 July 2026 in SharePoint on-premises?

On the 14 July 2026 Patch Tuesday, Microsoft published a fix for CVE-2026-50522, a deserialization of untrusted data vulnerability in SharePoint Server that permits unauthenticated remote code execution with a CVSS score of 9.8. Affected products are SharePoint Server Subscription Edition, SharePoint Server 2019 and SharePoint Server 2016 Enterprise. Following release of a public proof of concept, security firm watchTowr reported observing active in-the-wild exploitation, and CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalogue on 22 July 2026 with a 25 July 2026 federal remediation deadline. SecurityWeek noted it is the fourth SharePoint vulnerability exploited in a month, extending a summer run of on-premises collaboration compromises.

Why does patching CVE-2026-50522 not fully evict the attacker?

Because the watchTowr reporting is explicit that post-exploitation activity included theft of ASP.NET machine keys — the cryptographic material SharePoint uses to sign and encrypt ViewState, forms authentication tickets and session cookies. Once an attacker has exfiltrated the ValidationKey and DecryptionKey, applying the Microsoft patch closes the deserialization endpoint the attacker used to gain code execution, but does not invalidate the keys. The attacker can subsequently forge ViewState payloads offline, sign and encrypt them with the stolen keys, and deliver them to any SharePoint page that accepts ViewState — most of them do. The forged payloads pass signature validation using the buyer's own keys, deserialize into a gadget chain, and execute code on a fully patched farm without dropping a webshell on disk.

How should ASP.NET machine keys be rotated on a SharePoint farm after the patch?

After patching each server on the farm, rotate the ValidationKey and DecryptionKey in the web.config (or through the SharePoint / IIS management path appropriate to the farm topology), propagate the new keys consistently across every node in the farm so ViewState signed by any node validates on any other, and issue an iisreset on each node to force worker-process recycling and drop cached secrets from memory. Any ViewState signed with the old keys — including any payload the attacker prepared for post-patch use — will then fail signature validation and be rejected. Rotation without iisreset is incomplete; rotation on a subset of nodes leaves a validation path open on the un-rotated ones.

What does an assume-breach threat hunt cover on SharePoint after CVE-2026-50522?

The minimum hunt covers webshells and dropped binaries in the SharePoint LAYOUTS, TEMPLATE and _catalogs paths and in the IIS wwwroot more broadly; scheduled tasks and Windows services created or modified during the exposure window, especially those running as SYSTEM, the SharePoint service account or a farm admin; local and domain accounts created, modified or added to privileged groups such as SharePoint_Shell_Access or WSS_Admin_WPG; anomalous outbound connections from SharePoint servers to cloud storage, code hosting and paste sites; IIS access logs for oversized or unusual ViewState payloads on pages that should not carry much state; Windows event logs for suspicious w3wp.exe child processes such as cmd.exe, powershell.exe, certutil.exe, bitsadmin.exe and rundll32.exe; and PowerShell script-block and module logs for encoded commands, download cradles and reflective assembly loads. Output is a signed artefact even when it finds nothing.

What is a defensible emergency patch SLA for SharePoint on-premises in 2026?

A defensible 2026 target is CISA KEV listing patched within 24 to 72 hours on internet-exposed collaboration surfaces, and Microsoft critical advisory patched within 72 hours in any case. For CVE-2026-50522 specifically, the CISA KEV deadline was 25 July 2026, three days after listing on 22 July, so a partner unable to hit that clock is running a monthly maintenance cadence that no longer fits the disclosure-to-exploitation window observed on SharePoint in July 2026. Non-production and extranet zones are patched on the same clock because a partially patched estate is where post-patch persistence via forged ViewState lands most easily.

How should segmentation and the SharePoint service account be hardened?

The blast radius of a SharePoint compromise is a function of what the SharePoint service account can reach. Segment the SharePoint tier so SharePoint servers only initiate connections to their SQL back-end, their configured search and user-profile services and declared integrations; block arbitrary internal or internet egress from the SharePoint tier. Least-privilege the SharePoint service account so it holds no local administrator on non-SharePoint machines, no domain admin, and no privileged rights on the SQL host beyond what the SharePoint installer strictly requires. Combined with 24/7 MDR that includes SharePoint-aware detection content — suspicious w3wp.exe child processes, machine-key file access outside patching windows, changes to web.config, unusual ViewState traffic — these controls turn a farm compromise into an isolable incident rather than a domain compromise.

How does Call IT Dev deliver the CVE-2026-50522 managed-security playbook from Morocco?

Call IT Dev operates cybersecurity, technical support and cloud infrastructure engagements from Morocco with nearshore EU-time-zone coverage, delivery in English, French, Spanish and Arabic, and a regulatory posture aligned with CNDP Law 09-08 and GDPR obligations. The engagement applies the six-point playbook end-to-end: living inventory of SharePoint on-premises exposure reconciled weekly to an external attack-surface scan, emergency patch SLA on the collaboration stack in numeric terms, ASP.NET machine-key rotation with iisreset on every node after patch, assume-breach threat hunt across the pre-patch window with a signed artefact regardless of finding, segmentation and least-privilege on the SharePoint service account, and 24/7 MDR with SharePoint-aware detection content.

CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777