Skip to content
Critical SharePoint RCE Vulnerability Exploited for Key Theft

Critical SharePoint RCE Vulnerability Exploited for Key Theft

First seen 22 Jul 2026, 15:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 23, 2026 at 14:55 UTC
  • CVE-2026-50522 is a critical RCE vulnerability in Microsoft SharePoint.
  • Active exploitation began shortly after the release of public exploit code on July 22, 2026.
  • Attackers are stealing IIS machine keys, enabling long-term unauthorized access.

A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for long-term unauthorized access. The vulnerability was published on July 14, 2026, and public exploit code was released on July 22, leading to immediate exploitation attempts. WatchTowr reported successful attacks on July 20, indicating a rapid escalation in threat. Affected systems include SharePoint Server Subscription Edition and SharePoint Server 2019. The exploitation poses significant risks, including data theft and potential ransomware attacks. Organizations are advised to patch immediately and rotate their machine keys to mitigate the risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 51d ago How this analysis works

Timeline

2026-07-14
CVE-2026-50522 published
Microsoft disclosed a critical remote code execution vulnerability in SharePoint affecting on-premise deployments.
Feeds2.Feedburner
2026-07-20
Active exploitation observed
WatchTowr reported successful exploitation attempts against SharePoint servers, indicating immediate risk.
Feeds2.Feedburner
2026-07-22
Public exploit code released
The first proof-of-concept exploit for CVE-2026-50522 was made public, escalating the threat level.
Feeds2.Feedburner

More articles in this cluster (3)

Following this threat?

Track CVE-2026-50522 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed