Patching SharePoint is no longer the whole job. Attackers are using CVE-2026-50522 to take IIS machine keys, so a fixed server can stay trusted long after the code flaw is closed.
CERT-EU and WatchTowr say the exploitation is happening on on-prem SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The new risk is not just code execution on the server; it is theft of the signing material that lets an attacker keep minting requests that look legitimate.
Microsoft has already shipped the fix, but the trust loss can outlast it. If those keys were exposed, the server may be patched and still under the attacker’s control until the signing secrets are rotated and the compromise is assessed.