CRITICAL
Critical SharePoint RCE Exploited to Steal Machine Keys
Attackers are actively exploiting CVE-2026-50522, a critical remote code execution flaw in on-premises Microsoft SharePoint, to steal machine keys. Stolen machine keys let attackers forge authentication tokens and maintain access even after the RCE itself is patched, since patching doesn’t rotate keys already exfiltrated. Organizations running on-prem SharePoint should patch CVE-2026-50522 and rotate machine keys as part of remediation, not treat the patch alone as sufficient. Scale of exploitation and attribution were not specified in the report.