Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Overview
Attackers are actively exploiting a serious remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-50522. This vulnerability allows them to extract the IIS machine keys from on-premise SharePoint servers, enabling long-term access to the compromised systems. Following the release of public exploit code, researchers from WatchTowr reported successful attacks occurring just hours later. Companies using on-premise SharePoint installations need to be particularly vigilant, as the stolen machine keys can facilitate ongoing unauthorized access. It's crucial for organizations to patch this vulnerability promptly and take additional measures to secure their machine keys to prevent future exploitation.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Microsoft SharePoint (on-premise deployments)
- Action Required: Organizations should apply the latest security patches for SharePoint and rotate their IIS machine keys to mitigate the risk of unauthorized access.
- Timeline: Newly disclosed
Original Article Summary
Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday. WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and … More → The post Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) appeared first on Help Net Security.
Impact
Microsoft SharePoint (on-premise deployments)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Organizations should apply the latest security patches for SharePoint and rotate their IIS machine keys to mitigate the risk of unauthorized access. Specific patch numbers or updates were not mentioned in the article, so users should check for the most recent updates from Microsoft.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Microsoft, Exploit, and 4 more.
Multiple Sources: This threat is being reported by 3 different security sources, indicating significant concern within the cybersecurity community.