← Back

Wire · regulatory

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Published

21 July 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Source

Read at thehackernews.com

Verified

Fusion42 · 21 July 2026 · Fusion42 review

CVE-2026-50522, a critical remote code execution flaw in Microsoft SharePoint Server, is under active exploitation following public PoC release. Attackers authenticated as Site Owner can execute arbitrary code and steal machine keys for persistent access.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.

◆ The Wire takeaway

If you're selling to enterprises running SharePoint on-premises, their machine keys are being stolen right now—patch alone won't stop active attackers. You have a three-week window to help them rotate credentials before persistence becomes undetectable.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

CybersecurityEnterprise Softwaresharepoint-rcecve-2026-50522active-exploitationmachine-keyspersistence