CVE-2026-50522 used to steal keys and persist via SharePoint compromise
Source headline: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks
Intelligence Summary
A SharePoint vulnerability identified as CVE-2026-50522 is reportedly being actively exploited. Attackers use the flaw to steal machine keys that can help them maintain access over time. The activity is described as part of a broader wave of intrusions seen in the past month. Because machine keys can enable long-term impersonation, organizations may face persistent unauthorized access even after initial detection. SharePoint administrators should review exposure, ensure patches are applied, and hunt for signs of key theft and session persistence.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.