Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In

    July 31, 2026

    Montana’s new “right to try” law can’t come soon enough for some

    July 31, 2026

    The New Friend AI Pendant Can Now Talk Back to You

    July 31, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In
    • Montana’s new “right to try” law can’t come soon enough for some
    • The New Friend AI Pendant Can Now Talk Back to You
    • The Download: Montana’s new experimental drug rules
    • Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
    • Anthropic Says Claude Hacked 3 Organizations During Cybersecurity Tests
    • Indigenous Fiber Network Connects Remote Subarctic Towns
    • Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
    Cybersecurity

    Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 22, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys.

    “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday.

    WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and less than a week after Microsoft confirmed that CVE-2026-56164 (an privilege elevation flaw) and CVE-2026-58644 (a RCE vulnerability) are being actively exploited by attackers.

    On July 17, threat intelligence firm Defused also spotted what they now believe to be CVE-2026-50522 exploitation attempts.

    “The captured requests carry no authentication material, matching 50522’s unauthenticated profile. Microsoft describes the paired CVE-2026-58644 as requiring Site Owner auth, which does not fit unauthenticated traffic,” they commented on Monday.

    If they are right, it means that exploitation of CVE-2026-50522 started before the PoC exploit was released, but after Microsoft pushed out fixes for both flaws – earlier this month for CVE-2026-50522 and in June 2026 for CVE-2026-58644.

    Patching alone won’t lock attackers out

    Attackers are continuously trying to breach SharePoint servers, as they are usually reachable from the internet, hold valuable organizational data, and are integrated with other internal systems.

    Internet intelligence company Censys recently mapped internet-facing SharePoint servers and says almost all of them are SharePoint Online, which are hosted, operated and patched by Microsoft.

    “Counting hosts rather than web properties, about 1,500 run the self-managed, on-premises editions, predominantly SharePoint 2019 with smaller fractions identifying as 2016 and Subscription Edition,” they noted, and said that most of these are in the US.

    How many of these have received the latest security updates is impossible to tell, Censys added, because “the SharePoint response header (…) limits how precisely patch status can be assessed.”

    The US Cybersecurity and Infrastructure Security Agency issued a warning last week about a slew of SharePoint vulnerabilities targeted by attackers and urged organizations running self-managed server instances to:

    • Implement security updates quickly
    • Verify that Antimalware Scan Interface (AMSI) integration is enabled for each SharePoint web application (and monitor for detections)
    • Implement a number of hardening measures
    • Hunt for and remediate any intrusion artifacts before rotating IIS machine keys

    Organizations that haven’t yet implemented the SharePoint updates released on July 14 should not skip that last step.

    “Patching is not enough, defenders should rotate credentials on any assets that may have been exposed,” watchTowr advised.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    CVE202650522 exploited keys machine Patch RCE Rotate SharePoint
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In
    • Montana’s new “right to try” law can’t come soon enough for some
    • The New Friend AI Pendant Can Now Talk Back to You
    • The Download: Montana’s new experimental drug rules
    • Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting

    AI Slop Melodramas Are Taking Over X—and Their Creators Are Cashing In

    July 31, 2026

    Montana’s new “right to try” law can’t come soon enough for some

    July 31, 2026

    The New Friend AI Pendant Can Now Talk Back to You

    July 31, 2026

    The Download: Montana’s new experimental drug rules

    July 31, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.