Neat Digest  ·  Archive  ·  Open in app ↗

Critical SharePoint RCE flaw exploited to steal machine keys

Score 5.6/10 · Significant · Technology · 2 sources · July 21, 2026
Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting a critical remote code execution vulnerability, CVE-2026-50522, in Microsoft SharePoint. The flaw allows attackers to steal machine keys, enabling them to maintain persistent access to compromised servers even after the vulnerability is patched. The attack involves obtaining the machine keys and using them to forge authentication tokens or decrypt data. Microsoft has released a security update, but organizations that have not applied it or have not rotated their machine keys remain at risk. The exploitation is ongoing and targets both on-premises and cloud-connected SharePoint environments. Security researchers have observed multiple threat groups leveraging this vulnerability in the wild.

Global Impact

This vulnerability has significant cybersecurity implications. Economically, it drives increased spending on incident response, key rotation, and security audits for affected organizations.

Why this score

Neat Digest rated this story 5.6/10 — Significant tier.

Significant tier: actively exploited critical vulnerability in a widely used enterprise platform with a persistence mechanism that bypasses patching, affecting thousands of organizations globally and driving immediate cybersecurity spending and regulatory attention.

Sources on this story

Reported by 2 sources, including:

  • The Hacker News
  • BleepingComputer