Critical SharePoint RCE Vulnerability Exploited for Key Theft

Critical SharePoint RCE Vulnerability Exploited for Key Theft

First seen 22 Jul 2026, 15:25 UTC CybersecuritynewsFeeds2.Feedburner 73% similarity 72.8

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for long-term unauthorized access. The vulnerability was published on July 14, 2026, and public exploit code was released on July 22, leading to immediate exploitation attempts. WatchTowr reported successful attacks on July 20, indicating a rapid escalation in threat. Affected systems include SharePoint Server Subscription Edition and SharePoint Server 2019. The exploitation poses significant risks, including data theft and potential ransomware attacks. Organizations are advised to patch immediately and rotate their machine keys to mitigate the risk.

Key Points: • CVE-2026-50522 is a critical RCE vulnerability in Microsoft SharePoint. • Active exploitation began shortly after the release of public exploit code on July 22, 2026. • Attackers are stealing IIS machine keys, enabling long-term unauthorized access.

ThreatCluster AI

Timeline

2026-07-14
CVE-2026-50522 published
Microsoft disclosed a critical remote code execution vulnerability in SharePoint affecting on-premise deployments.
Feeds2.Feedburner
2026-07-20
Active exploitation observed
WatchTowr reported successful exploitation attempts against SharePoint servers, indicating immediate risk.
Feeds2.Feedburner
2026-07-22
Public exploit code released
The first proof-of-concept exploit for CVE-2026-50522 was made public, escalating the threat level.
Feeds2.Feedburner

Community

Browse all →