Vulnerabilities · 54 days ago

SharePoint Patch Leaves Trusted Access Behind

Patching SharePoint is no longer the whole job. Attackers are using CVE-2026-50522 to take IIS machine keys, so a fixed server can stay trusted long after the code flaw is closed.

CERT-EU and WatchTowr say the exploitation is happening on on-prem SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The new risk is not just code execution on the server; it is theft of the signing material that lets an attacker keep minting requests that look legitimate.

Microsoft has already shipped the fix, but the trust loss can outlast it. If those keys were exposed, the server may be patched and still under the attacker’s control until the signing secrets are rotated and the compromise is assessed.

CVE-2026-50522

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over… Microsoft patch: 5002891.

Patch available KB5002891 Download →

CISA federal remediation date Jul 25

Timeline

Sources

14 sources covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-07-26

Editions

Related stories