Attackers are actively exploiting CVE-2026-50522, a critical remote code execution vulnerability in Microsoft SharePoint, to extract machine keys that persist even after patches are applied. The flaw enables long-term access to compromised systems.
Microsoft SharePoint users face an ongoing threat from CVE-2026-50522, a critical remote code execution vulnerability currently being exploited in the wild. The flaw allows attackers to execute arbitrary code on affected servers and extract machine keys—cryptographic credentials that authenticate applications and services.
■ The Persistence Problem
Machine keys are particularly dangerous because they remain valid even after affected systems are patched. Attackers who obtain these keys can maintain access to networks and applications independently of the original vulnerability. This means organizations patching SharePoint may unknowingly remain compromised.
■ Active Exploitation
Security researchers have confirmed active exploitation attempts targeting unpatched SharePoint instances. The vulnerability affects multiple versions of the platform, making it a widespread concern across enterprise environments.
■ Recommended Actions
Microsoft recommends immediate patching of all vulnerable SharePoint installations. Organizations should:
- Apply security updates as soon as possible
- Audit logs for suspicious activity tied to the CVE identifier
- Review and rotate machine keys on affected systems
- Monitor for unauthorized access attempts using extracted credentials
- Check for any lateral movement or data exfiltration
■ Broader Impact
The exploitation of this flaw underscores the urgency of patch management in enterprise infrastructure. SharePoint's role in document management and collaboration makes it a high-value target for attackers seeking network persistence.
Organizations that discover they have been compromised should assume attackers may have obtained machine keys and implement additional access controls and monitoring until full remediation is confirmed.
Apple defeated liability claims for not scanning iCloud photos for child sexual abuse material (CSAM), though the presiding judge expressed clear disapproval of the company's position.
A massive operation called FakeGit has weaponized over 7,600 GitHub repositories to distribute SmartLoader and StealC malware, accumulating more than 14 million downloads across the platform.
Cisco released two open-weight AI models, Antares-350M and Antares-1B, designed to identify known vulnerabilities in codebases. The company plans to release a larger Antares-3B model soon.
Hackers are actively exploiting critical vulnerabilities in WordPress Core to deploy persistent webshells and malicious plugins. The wp2shell vulnerability suite affects multiple WordPress installations globally.