Summary
Microsoft SharePoint on-premises servers are under active attack following the release of exploit code for CVE-2026-50522. Attackers are stealing machine keys to maintain persistent access.
Take Action:
If you run on-premises SharePoint, apply Microsoft's July 14 patch immediately to fix CVE-2026-50522. Note that patching alone is not enough, because attackers steal the server's machine keys and keep access afterwards. Rotate all machine keys and related credentials on any exposed server, and check your logs for signs someone already extracted them.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)