CVE Tools
Back to feed
Exploited in the wild SharePoint rce Microsoft web-app

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Help Net Security·By Zeljka Zorz··2 min read
CVE Tools coverage

A critical remote code execution flaw in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to extract IIS machine keys from vulnerable servers. Offensive security firm WatchTowr reported that exploitation began shortly after a proof-of-concept was made public, allowing unauthorized access without authentication. The vulnerability affects on-premise SharePoint installations, and experts warn that simply applying patches isn't sufficient—organizations must also rotate their IIS machine keys to fully secure their systems.