Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
ID: 0966bac3-4aaf-53bc-bb98-629ef4ec2d62
STIX ID: report--0966bac3-4aaf-53bc-bb98-629ef4ec2d62
Feed Name: Help Net Security
**Active exploitation of SharePoint RCE (CVE-2026-50522) observed:** Security firms (WatchTowr, Defused) report attackers are exploiting a critical unauthenticated SharePoint RCE to extract IIS machine keys for persistent access, with successful attempts recorded shortly after PoC release; Censys estimates ~1,500 on-prem SharePoint hosts potentially exposed. CISA and vendors urge rapid patching, AMSI enablement, hardening, intrustion hunts and rotation of IIS machine keys because patching alone may not evict attackers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
