1 article on this topic.
A public PoC for a critical on-premises SharePoint deserialization flaw is being actively exploited within hours of release — and the payload attackers want isn't a shell, it's your machine keys.