Security researchers this week confirmed hackers are actively attacking a critical flaw in Microsoft SharePoint Server, tracked as CVE-2026-50522, that can let an attacker take over an on-premises SharePoint server over the network. The bug carries a severity score of 9.8 out of 10 — one of the highest possible — and researchers are already comparing the campaign to the massive 'ToolShell' wave that hit hundreds of organizations in the summer of 2025.
What the flaw does
The flaw is a critical-severity deserialization vulnerability in Microsoft SharePoint tracked as CVE-2026-50522, with a severity rating of 9.8 out of 10 that could enable an attacker to execute remote code over a network. In plain English: an attacker on the internet can run their own code on a vulnerable SharePoint server without needing a password.
Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, and researchers warned that attackers are stealing machine keys to maintain long-term access. That last part matters — once those cryptographic keys are stolen, simply patching the server later doesn't automatically kick the attacker back out.
The initial disclosure was part of a larger July 14 patch release by Microsoft.
Why researchers are calling it 'ToolShell-class'
According to watchTowr's team, the latest exploit has 'ToolShell-class impact.' ToolShell was a summer 2025 campaign by ransomware and state-linked groups where hundreds of SharePoint customers were compromised, and multiple federal agencies were hit in the attacks.
The resemblance to July 2025's ToolShell campaign is real — both target internet-facing SharePoint servers, and both can lead to machine-key theft and persistent access. It should not, however, be treated as the same campaign. Different bug, same playbook.
This is not a bug in SharePoint Online (the Microsoft 365 cloud version). It only affects organizations running their own on-premises SharePoint Server — which in York County usually means law offices, medical practices, manufacturers, and other small-to-midsize businesses that host their own document server.
What to do this week
Microsoft released security updates to address CVE-2026-50522 and said customers should upgrade to the latest version. The company is not aware of any exploitation prior to publishing the CVE, and a spokesperson said the security update fully mitigates the issue, however rotating machine keys can be performed to further safeguard user environments.
Three action items if your business runs on-premises SharePoint:
1. Install the July 14, 2026 Microsoft security update on the SharePoint server immediately. 2. Rotate the ASP.NET machine keys after patching. Patching alone is not enough if attackers already grabbed the keys. 3. Look for signs of compromise — unexpected web shells, new admin accounts, or unusual outbound traffic from the server.
If you're not sure whether your server was reachable from the public internet, assume it was and check the logs. Small businesses that discover suspicious activity should treat it as a potential ransomware precursor and consider bringing in help to clean out any malware footholds before the attackers escalate. And if a workstation on the same network starts acting up — sluggish performance, files that won't open, ransom notes — stop using it and get the drive imaged so you can recover important files before anything is overwritten.
Regular PC users: what this means for you
If you don't run a SharePoint server, this specific bug doesn't affect your home or office PC directly. But the broader pattern matters: Microsoft found that bad actors are using AI to find bugs in Windows and actively exploit unpatched systems. That means the window between a patch being released and criminals attacking unpatched machines keeps shrinking.
The short version: install Windows updates within a few days of release, keep a real backup of your files, and don't ignore the reboot prompt for weeks at a time. If your PC has been refusing updates, freezing during install, or throwing errors, that's worth having a technician look at the machine rather than leaving it stuck on an old, vulnerable build.
What This Means for York, PA
York-area law firms, medical offices, and manufacturers that host their own SharePoint server should patch this week and rotate machine keys — the exploit is already in the wild. If you're not sure whether your business is exposed or you need hands-on help checking a suspect PC on the same network, York Computer Repair can take a look during walk-in hours at 2069 Carlisle Rd.