Feeds2.Feedburner Critical SharePoint RCE Vulnerability Exploited for Key Theft
Article Content
- •CVE-2026-50522 is a critical RCE vulnerability in Microsoft SharePoint.
- •Active exploitation began shortly after the release of public exploit code on July 22, 2026.
- •Attackers are stealing IIS machine keys, enabling long-term unauthorized access.
A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for long-term unauthorized access. The vulnerability was published on July 14, 2026, and public exploit code was released on July 22, leading to immediate exploitation attempts. WatchTowr reported successful attacks on July 20, indicating a rapid escalation in threat. Affected systems include SharePoint Server Subscription Edition and SharePoint Server 2019. The exploitation poses significant risks, including data theft and potential ransomware attacks. Organizations are advised to patch immediately and rotate their machine keys to mitigate the risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-50522 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in Windows IKE Actively Exploited A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported versions of Windows 10, Windows 11, and Windows Server. Attackers can exploit the vulnerability…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…