Critical SharePoint RCE Vulnerability Exploited for Key Theft
ID: 4dcb1095-e0bc-537d-a533-3a96dfb5b1b5
STIX ID: report--4dcb1095-e0bc-537d-a533-3a96dfb5b1b5
Feed Name: ThreatCluster
Critical RCE (CVE-2026-50522) in Microsoft SharePoint is being actively exploited against on-premises SharePoint Server Subscription Edition and SharePoint Server 2019; attackers are extracting IIS machine keys to enable persistent unauthorized access. Public exploit code was released on July 22, 2026, with exploitation observed shortly thereafter (reports from WatchTowr indicate successful attacks), creating immediate risk of data theft and potential follow-on ransomware. Organizations are advised to patch immediately and rotate machine keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
