CRITICAL ⚡ MUST-KNOW
Fourth SharePoint Vulnerability Exploited to Steal Machine Keys
CVE-2026-50522 is being actively exploited by threat actors in an ongoing wave of SharePoint attacks — the fourth distinct vulnerability exploited in this campaign over the past month. Attackers are using it to steal SharePoint machine keys, which grants long-term persistent access even after the underlying vulnerability is patched. Organizations running on-prem SharePoint should patch immediately and rotate machine keys as part of remediation, not just apply the fix.