Vulnerabilità · 68 giorni fa
SharePoint patchato, ma le chiavi restano in mano all'attaccante Il punto non è più solo chiudere la RCE. Su SharePoint on-prem, CVE-2026-50522 può diventare un problema di persistenza: se l'attaccante estrae le IIS machine keys, un server patchato può continuare ad accettare richieste che sembrano legittime.
CERT-EU e WatchTowr confermano lo sfruttamento in the wild dopo il rilascio del proof-of-concept pubblico. Le fonti parlano di Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019 e SharePoint Enterprise Server 2016; Microsoft ha corretto la falla il 14 luglio, ma l'aggiornamento non basta a chiudere una compromissione già passata dalle chiavi.
Per gli ambienti esposti su Internet, il rischio non resta confinato alla singola CVE: una volta rubate le chiavi di firma, l'attaccante può continuare a impersonare traffico fidato anche dopo la patch. Il problema diventa quindi la fiducia residua, non solo il bug iniziale.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 25 lug
Cronologia Fonti 14 fonti che coprono questa storia
Help Net Security 22 lug
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) - Help Net Security
Attackers are exploiting an unauthenticated SharePoint RCE vulnerability (CVE-2026-50522) to extract the servers' IIS machine keys.
SecurityWeek 22 lug
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
CERT-EU Advisories 22 lug
Critical Vulnerabilities in Microsoft SharePoint
The Hacker News 21 lug
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
watchTowr reports active exploitation of SharePoint CVE-2026-50522 after a public PoC, with attackers stealing machine keys for persistence.
BleepingComputer 21 lug
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
Cybersecurity Dive 21 lug
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.
Rapid7 17 lug
CVE-2026-58644 Microsoft Sharepoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments.
Infosecurity Magazine 17 lug
CISA Mandates Urgent Patch for Actively Exploited Fortinet Flaws
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
SecurityWeek 17 lug
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.
Tenable 16 lug
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable®
CISA confirmed exploitation of three SharePoint Server CVEs.
CSIRT Italia / ACN 16 lug
Aggiornamenti Mensili Microsoft
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 622 nuove vulnerabilità, di cui 2 di tipo 0-day.
CSO Online 16 lug
CISA urges immediate SharePoint hardening as exploits mount
Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that patching alone won’t prevent business disruption.
Entità Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-07-26
Editions Storie correlate
Vulnerabilità · 68 giorni fa
SharePoint patchato, ma le chiavi restano in mano all'attaccante Il punto non è più solo chiudere la RCE. Su SharePoint on-prem, CVE-2026-50522 può diventare un problema di persistenza: se l'attaccante estrae le IIS machine keys, un server patchato può continuare ad accettare richieste che sembrano legittime.
CERT-EU e WatchTowr confermano lo sfruttamento in the wild dopo il rilascio del proof-of-concept pubblico. Le fonti parlano di Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019 e SharePoint Enterprise Server 2016; Microsoft ha corretto la falla il 14 luglio, ma l'aggiornamento non basta a chiudere una compromissione già passata dalle chiavi.
Per gli ambienti esposti su Internet, il rischio non resta confinato alla singola CVE: una volta rubate le chiavi di firma, l'attaccante può continuare a impersonare traffico fidato anche dopo la patch. Il problema diventa quindi la fiducia residua, non solo il bug iniziale.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over… Patch Microsoft: 5002891.
Patch disponibile KB5002891 Scarica →
Data di correzione federale CISA 25 lug
Cronologia Fonti 14 fonti che coprono questa storia
Help Net Security 22 lug
Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) - Help Net Security
Attackers are exploiting an unauthenticated SharePoint RCE vulnerability (CVE-2026-50522) to extract the servers' IIS machine keys.
SecurityWeek 22 lug
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
CVE-2026-50522 is being exploited by threat actors to steal machine keys and retain long-term access.
CERT-EU Advisories 22 lug
Critical Vulnerabilities in Microsoft SharePoint
The Hacker News 21 lug
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
watchTowr reports active exploitation of SharePoint CVE-2026-50522 after a public PoC, with attackers stealing machine keys for persistence.
BleepingComputer 21 lug
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
Cybersecurity Dive 21 lug
Microsoft SharePoint under attack via new exploit
Security researchers warn the potential risk could rival the widespread ToolShell campaign of 2025.
Rapid7 17 lug
CVE-2026-58644 Microsoft Sharepoint Server Unauthenticated Remote Code Execution Vulnerability Exploited in the Wild
On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments.
Infosecurity Magazine 17 lug
CISA Mandates Urgent Patch for Actively Exploited Fortinet Flaws
US government agencies have until July 19 to patch two critical Fortinet vulnerabilities
SecurityWeek 17 lug
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
The critical-severity security defect allows remote, authenticated attackers to execute arbitrary code on the server.
Tenable 16 lug
SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable®
CISA confirmed exploitation of three SharePoint Server CVEs.
CSIRT Italia / ACN 16 lug
Aggiornamenti Mensili Microsoft
Microsoft ha rilasciato gli aggiornamenti di sicurezza mensili che risolvono un totale di 622 nuove vulnerabilità, di cui 2 di tipo 0-day.
CSO Online 16 lug
CISA urges immediate SharePoint hardening as exploits mount
Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that patching alone won’t prevent business disruption.
Entità Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-07-26
Editions Storie correlate