Exploited in the wild SharePoint rce Microsoft web-app
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
CVE Tools coverage
A critical remote code execution flaw in Microsoft SharePoint, tracked as CVE-2026-50522, is currently being actively exploited by attackers to extract IIS machine keys from vulnerable servers. Offensive security firm WatchTowr reported that exploitation began shortly after a proof-of-concept was made public, allowing unauthorized access without authentication. The vulnerability affects on-premise SharePoint installations, and experts warn that simply applying patches isn't sufficient—organizations must also rotate their IIS machine keys to fully secure their systems.