logo

Critical SharePoint RCE Vulnerability Exploited for Key Theft

ID: 4dcb1095-e0bc-537d-a533-3a96dfb5b1b5

STIX ID: report--4dcb1095-e0bc-537d-a533-3a96dfb5b1b5

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-07-22

...
...

Critical RCE (CVE-2026-50522) in Microsoft SharePoint is being actively exploited against on-premises SharePoint Server Subscription Edition and SharePoint Server 2019; attackers are extracting IIS machine keys to enable persistent unauthorized access. Public exploit code was released on July 22, 2026, with exploitation observed shortly thereafter (reports from WatchTowr indicate successful attacks), creating immediate risk of data theft and potential follow-on ransomware. Organizations are advised to patch immediately and rotate machine keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.