Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
Reported exploitedSharePointOur summary
A critical remote code execution flaw in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to extract IIS machine keys from vulnerable servers. Offensive security firm WatchTowr reported that exploitation began shortly after a proof-of-concept was made public, allowing unauthorized access without authentication. The vulnerability affects on-premise SharePoint installations, and experts warn that simply applying patches isn't sufficient—organizations must also rotate their IIS machine keys to fully secure their systems.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.