CRITICAL: Microsoft SharePoint RCE CVE-2026-50522 Exploited in the Wild to Steal Machine Keys
A critical CVSS 9.8 deserialization flaw in on-premises Microsoft SharePoint Server, CVE-2026-50522, is under active exploitation after a public proof-of-concept. Attackers are executing remote code and stealing SharePoint machine keys for persistence that survives patching. Patch immediately and rotate machine keys.