ZeroHour
Security Affairspublished ()ingested @securityaffairs1

SharePoint Flaws Used to Hack Switzerland's Federal IT Agency

criticalRansomware exploited in the wildimportance 60CVE-2026-50522

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-50522
Unauthenticated Deserialization RCE in Microsoft SharePoint Server

CVE-2026-50522 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows an unauthenticated attacker to send maliciously crafted serialized data over the network and execute code on the server, reflected in its 9.8 critical CVSS score with no privileges or user interaction required. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, giving attackers a foothold for follow-on actions such as data theft, lateral movement, or ransomware. Any organization running on-premises SharePoint Server is in scope, particularly deployments reachable from untrusted networks; the required action notes stakeholders must evaluate each asset's internet exposure under CISA BOD 26-04. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-22 and security news headlines describe it as a critical RCE exploited in the wild, with some reports referencing exploitation after a public proof-of-concept release and an authentication bypass. The structured record lists no public PoC as confirmed, but an EPSS of 84.6% (100th percentile) underscores a very high near-term exploitation likelihood.

Do: Apply Microsoft's security updates for SharePoint Server immediately per the vendor advisory, as required under CISA's KEV listing and BOD 26-04, and prioritize any SharePoint deployments that are internet-facing (federal/critical-infrastructure operators must follow BOD 26-04 timelines or discontinue unmitigated use). Until patched, restrict public access to SharePoint endpoints (VPN, firewall rules, or reverse proxy) and review IIS/application logs and running processes for signs of unauthenticated deserialization abuse. Because some reports reference an authentication bypass being chained, also verify authentication paths and monitor for follow-on attacker activity after patching.

9.885% KEV
  • Microsoft SharePoint Server (on-premises)
massorder of 100,000+ on-prem SharePoint Server deployments worldwide, with tens of thousands plausibly internet-exposed
Full article764 words · extracted from securityaffairs.com · click to collapse

Swiss Federal IT Agency FOITT says attackers exploited SharePoint flaws to compromise about 200 accounts. Servers are being rebuilt as investigations continue.

Switzerland’s Federal Office for Information Technology and Communications, known as BIT or FOITT, disclosed that unknown attackers had compromised approximately 200 accounts on its on-premises SharePoint servers. The FOITT said the unknown attackers are believed to have exploited vulnerabilities in Microsoft’s SharePoint software. The software manufacturer had reported several such vulnerabilities in mid-July.

The FOITT is the largest IT service provider in the Federal Administration. It provides around 50,000 workstation systems, develops customised, secure and user-friendly IT solutions together with the administrative units, and operates over 1,000 specialist applications, mainly in its own modern data centres.

The FOITT operated the servers in the federal government’s own data centres and, according to its own statements, had immediately begun installing the security updates provided. FOITT detected the anomalies on July 28 and confirmed the account compromise three days later, on July 31.

“The cyberattack was carried out by previously unknown actors, presumably by exploiting these vulnerabilities in the SharePoint software,” the Swiss agency said.

“During the course of their analysis, the experts discovered on July 31 that the login details for around 200 user and technical accounts had been compromised.” reports the media outlet Swiss Info. “According to its own statements, the FOITT immediately reset the relevant passwords. Based on the investigations to date, which are being supported by the National Cybersecurity Centre (NCSC) and Microsoft, there is no evidence of any further data leakage. However, the analysis is still ongoing.”

Both user and technical accounts were hit. On the same day anomalous access was detected, FOITT blocked external internet access to SharePoint and began patching. It’s now reinstalling the affected servers entirely as a precaution and has shared all relevant technical indicators with Swiss critical infrastructure operators through the national cybersecurity agency’s platform.

The July Patch Tuesday timing matters here. Microsoft disclosed multiple serious SharePoint vulnerabilities on July 14. One flaw, tracked as CVE-2026-50522 (CVSS score of 9.8) could enable an attacker to execute remote code over a network. Microsoft said exploitation would be considered low complexity, as an attacker does not require a great deal of knowledge of the system to complete an attack. Researchers warned that attackers are stealing machine keys to maintain long-term access. That last part is the critical detail: machine keys are the cryptographic secrets that IIS uses to sign session tokens, and once stolen they let an attacker forge legitimate-looking requests that a fully patched server will still accept.

The Swiss FOITT is reinstalling the affected SharePoint servers as a precaution after the cyber incident. External internet access remains blocked until the work is complete, while federal employees can still access and share documents through alternative channels. FOITT pointed out that the platform is not intended to store confidential information or highly sensitive personal data.

Patching closes the door; it doesn’t change the locks. SharePoint is increasingly targeted by cybercriminals and nation-state actors because of its deep integration with Microsoft authentication. Attackers exploiting vulnerabilities could use it as an entry point to compromise wider networks, making direct internet exposure of SharePoint servers a growing security risk.

“CERT-EU strongly recommends updating affected servers as soon as possible, rotating credentials for any assets that may have been vulnerable and exposed to the internet, and conducting a compromise assessment to identify potentially affected SharePoint instances.” CERT-EU’s advisory warns. “Given the number of recent critical vulnerabilities affecting SharePoint, organisations should reconsider exposing any Microsoft SharePoint Server directly to the internet.”

Neither Microsoft nor CISA have attributed the exploitations publicly to any specific threat group.

Switzerland’s National Cyber Security Centre (NCSC) recorded 28 cyberattacks targeting the Federal Administration in 2025 and 325 incidents affecting critical infrastructure, with about one in four involving public administration. One of the most notable cases hit the state-owned defense contractor Ruag, whose U.S. subsidiary was breached by the Akira ransomware group, leading to data theft and a ransom payment to recover the stolen information.

The practical takeaway for any organization still running on-premises SharePoint exposed to the internet: apply the July patches, then rotate your machine keys and restart IISm in that order, not one without the other. If you can’t take the server offline to reinstall it the way FOITT is doing, at minimum validate that external internet exposure has been eliminated. The window between vulnerability disclosure and active exploitation in this campaign was measured in days, not weeks.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196625/hacking/sharepoint-flaws-used-to-hack-switzerlands-federal-it-agency.html