Patching SharePoint is no longer the whole job. Attackers are using CVE-2026-50522 to take IIS machine keys, so a fixed server can stay trusted long after the code flaw is closed.
CERT-EU and WatchTowr say the exploitation is happening on on-prem SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The new risk is not just code execution on the server; it is theft of the signing material that lets an attacker keep minting requests that look legitimate.
Microsoft has already shipped the fix, but the trust loss can outlast it. If those keys were exposed, the server may be patched and still under the attacker’s control until the signing secrets are rotated and the compromise is assessed.
CVSS 9.8 CRITICAL: deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over… Microsoft patch: 5002891.
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
On July 14, 2026, Microsoft published a security advisory addressing CVE-2026-58644, a critical remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server deployments.
Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that patching alone won’t prevent business disruption.