Feeds2.Feedburner
Critical SharePoint RCE Vulnerability Exploited for Key Theft
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for long-term unauthorized access. The vulnerability was published on July 14, 2026, and public exploit code was released on July 22, leading to immediate exploitation attempts. WatchTowr reported successful attacks on July 20, indicating a rapid escalation in threat. Affected systems include SharePoint Server Subscription Edition and SharePoint Server 2019. The exploitation poses significant risks, including data theft and potential ransomware attacks. Organizations are advised to patch immediately and rotate their machine keys to mitigate the risk.
Key Points: • CVE-2026-50522 is a critical RCE vulnerability in Microsoft SharePoint. • Active exploitation began shortly after the release of public exploit code on July 22, 2026. • Attackers are stealing IIS machine keys, enabling long-term unauthorized access.