Wire · regulatory
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 21 July 2026 · Fusion42 review
CVE-2026-50522, a critical remote code execution flaw in Microsoft SharePoint Server, is under active exploitation following public PoC release. Attackers authenticated as Site Owner can execute arbitrary code and steal machine keys for persistent access.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.
◆ ◆ The Wire takeaway
If you're selling to enterprises running SharePoint on-premises, their machine keys are being stolen right now—patch alone won't stop active attackers. You have a three-week window to help them rotate credentials before persistence becomes undetectable.
◆ Coverage
1 source · 21 Jul 2026
◆ Related on Wire
◆ Topics