# Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

> **Open Intelligence Dossier** · First detected: 2026-07-21 20:07 UTC · Category: Technology

## Executive Summary
A critical remote code execution flaw in Microsoft SharePoint, CVE-2026-50522, is being actively exploited following the release of a public PoC.

## Intelligence Brief
Microsoft SharePoint is currently facing an active security crisis centered on a critical remote code execution vulnerability identified as CVE-2026-50522. According to reports from The Hacker News and CyberSecurityNews, this flaw is being exploited in the wild following the release of a public proof-of-concept. The technical nature of the attack allows for a single malicious web request to transform an exposed SharePoint server into a persistent backdoor. This capability enables attackers to move from an initial web request to a full domain compromise, as detailed in analysis provided by Resecurity. The vulnerability is facilitating the deployment of web shells and the theft of critical machine keys. Multiple industry outlets are tracking the escalation of these attacks.


BleepingComputer and SC Media emphasize that the exploit is specifically being used to steal machine keys, noting that this represents the fourth recent exploit of its kind. CyberSecurityNews further highlights the multifaceted nature of the threat, which includes remote code execution and the installation of web shells. Coverage from The National CIO Review links these SharePoint vulnerabilities with Windmill vulnerabilities, suggesting that both are fueling a fresh wave of enterprise-level attacks. Other regional and specialized reports, including those from Kaseya, have listed these events within their weekly breach news summaries for the period of July 15, 2026. Understanding the context of this trend requires noting the speed at which the public proof-of-concept transitioned into active exploitation. The vulnerability is categorized as critical because it grants attackers high-level access to servers via basic web requests.


As gbhackers.com points out, the ability to establish a persistent backdoor means that once a server is breached, the attackers can maintain access even after some initial remediation efforts. The focus on IIS key theft suggests that attackers are targeting the underlying infrastructure of the server to deepen their penetration into the corporate network, moving beyond the application layer to the domain level. Looking ahead, the primary focus for enterprise security teams is the mitigation of CVE-2026-50522 to prevent further domain compromises. Organizations are monitoring for signs of web shells and the unauthorized extraction of machine keys, as these are the primary indicators of a successful breach. Because the vulnerability is being actively exploited in the wild, the priority remains identifying exposed SharePoint servers that may have already been targeted by the malicious web requests described in the coverage. Future reports will likely track whether the exploitation of this flaw continues to rise in tandem with the Windmill vulnerabilities mentioned by The National CIO Review.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| The National CIO Review | Windmill and SharePoint Vulnerabilities Fuel Fresh Enterprise Attacks | [Source Link](https://news.google.com/rss/articles/CBMiygFBVV95cUxPVjF1X1ZreWZHaXdoOEpvTk5ueFoxNW1lbXAteFF3bnhoVGhGTl9xTkc4ZFMzQVlBSG1OTkpmOUxKR0RUS3hnV2ZMWHBMSmk5TnE5aXhuTmxHTDNhYzUzd1phMHdzTlFRdTdPb3ZzaWZVTVM1YWE2VjRlMmVsenk4ZW1IcWVMaV94eURtQThQMU1JaUhtOVlwcEd3WV9GSTVMajZBUXZaZVdYeVZ0aURWbl9sM01iR2hZd1p3N21XN0twYUZrajlGR19R?oc=5) |
| SC Media | SharePoint vulnerability steals machine keys; fourth recent exploit | [Source Link](https://news.google.com/rss/articles/CBMimwFBVV95cUxOaG5ERUY0MHphVUxsLTdadlYxQ2Fla1JiSkdfeDViMnN0WDI4eUxmeXMzaFZ2azZNZWlzSEpwYl9YWmJuOVBMV3NtMG01QnhkcVNUV1Z3czlJTm5yd1lzQ1pxX3hDaXVTUTBhQVBVdEVXanVOOVBQdUQyVzRocTFhT0tRaFlETDNUSHJZUE90ZGNsd1RtQXVrbmhpWQ?oc=5) |
| Kaseya | Die Woche in den Nachrichten zu Datenschutzverletzungen | [Source Link](https://news.google.com/rss/articles/CBMickFVX3lxTFBqU2xYbXBTTlNvUkpWSm8ydXpPQjV1UnB0bnhkWndBd1VxT2Y2dkN5RGNlMGR0cWFZdlZFOHBSd21Rb0J6cldtdUJzWU1Wc1FTN01RUzhRZnlQNTFKallRX0dXVGNDbkNEYXJ0LThIRU5uUQ?oc=5) |
| CyberSecurityNews | Critical SharePoint Remote Code Execution Vulnerability Actively Exploited in the Wild | [Source Link](https://news.google.com/rss/articles/CBMidkFVX3lxTFAwTXo2ckQzbW43YkdPal9ZMVFmazRXcFZkeUE5U1NDR0p1S0NSTy1kQUFYM3B0UzlXWFUyVmJYQ195NFFvY0sxTjBDZnk3VXkxRm04TU0zUjBYS05oVTdMWFlYaGk5cmF2QWJKcnZoT09MZW1Qd3fSAXtBVV95cUxPajN1UXdmT1ZRdzhzb2JoOFU0RVJNNXBxUHRaSDRZVTVJX1c5b01lZEt6V3EweG1lN1g2WjRJX05aNHJHS1pVc2xLVGk1bU1VZGk2MTRrbzEyaHFkTkhpU2YtekdneHdHWTB6VjZrSk9henNqajhhYXNnbEU?oc=5) |
| Resecurity | From Web Request to Domain Compromise: Understanding the July 2026 SharePoint Attacks | [Source Link](https://news.google.com/rss/articles/CBMiwgFBVV95cUxPWkd4ZXV3RkFIRlRVak94T0lqWW5WSHozX1ZBY2gxTTk2SmE0MWY1RzY1U21sbHVDcWsxVXB5LWNxX0g0UWJsRHZRRE5KN2d6UEl5eGtHNWY2TTc3Sk42TVFpVFkteF8tMmhVVVRBYm9IRk5KM0tBdG51REJoWHBfODFkOWN3QXpIbEE2ZVUxcDdhZkhMVXQzMU5tZ2w2MmxlTm9SN2hoeHBoTFYzbUVjZDRfUU5wWWRRTVdUZlI0bjhXdw?oc=5) |
| Kaseya | The Week in Breach News: July 15, 2026 | [Source Link](https://news.google.com/rss/articles/CBMiWkFVX3lxTE9HeW52ZGdCT1JBZE1kZ2J6dUlQRVM1aEZhbHpXaklUSXI1Vm1oUzdIMFFjNjcyNzNGRTdGT2hBYk9QN256T0pYQnNNNC1IVGhBS0o5TUNjX25kUQ?oc=5) |
| gbhackers.com | One Malicious Web Request Can Turn an Exposed SharePoint Server Into a Persistent Backdoor | [Source Link](https://news.google.com/rss/articles/CBMidEFVX3lxTE5wdVhRRUhCMS11TjRNQnVRZWFYbmxuRkJGOUNDUTA2MHByR3dqaS1HQW1rZlhHYWtsX1l5UENhNnJOWTV6b25GTGt5dDhqcXRodFJ4WFNxb3dfNVZrLXdBX01BQTZTSnRMaVRsV0dfby1hc0Ru0gF6QVVfeXFMTlRJV0NYT3MyN1lwVjh5OWIyaVc5ckhFTXY4bUxmRzl2dE8tY1ZtOTYwbHVGOU1wWGNSc1g1Q01ZeXRLdDk5Q3g4WUR2cFdNcmlxTnVxcVo0bGFOOFViQ2tZc1VCa3p6OWFnMUF4RXZ3QXk4MllPbGpTOHc?oc=5) |
| BleepingComputer | Critical SharePoint RCE flaw exploited to steal machine keys | [Source Link](https://news.google.com/rss/articles/CBMirAFBVV95cUxPWnpXQTAwcmEtRVlkNmQtWldmRTNySGlJWmJzajdheE0zREVOMmFpUGdhbUtvcUdNSUFMeUpxMkNEOEE2VWZyWFc5bFNmR0NyT3M5ZWNZdHlZWk9iMjFjYlVIclFwMUw1aHgteUsyak50SmxNQlVUeGd1WGJWNnBnQzg5NGx0NWdpb1VzUlhIemJPVEkzX3FGR21BOGNPV3RiSjMtUDM5cXZ0cDJN0gGyAUFVX3lxTFBMeGhaZkprMnk1U0w0SHIxNkE2NVZyMml3clhwZ0ZQeFFLQV9oRFdleUsxNjEtSEhWQ21xV1c5dmdfeVVvZkZObE5RR3NUS1lpa1dOS3p5QWppM3Z5RWVHNVRjREc5NWpxUEVJaWhWWm5OTks3LWUyOTgxMDc0YlFBQThxbWxDTTlrRTVqWjVtc1pKNll0TWpqVERFeUlVa2ZNUUd5dmp) |
| CyberSecurityNews | Microsoft SharePoint Vulnerabilities Actively Exploited for RCE, Web Shells, and IIS Key Theft | [Source Link](https://news.google.com/rss/articles/CBMidkFVX3lxTFAteGFlMmtfQlhndWx0M2hDRmJxYnFJYVRrSktiSkpLNEROZlZnVW5ieHVNTWh3bFlvN25iRHB0QzhaeVo1VU52aXhUUEhhSzFjaDhadTQxd0RvSVFwSzY4aDFiWllpQjUwY1AtZkI5Ulo5c3J3eGfSAXtBVV95cUxQVzlsc0toU3NTTnNwSldxNDZWQ0NrcEVkYnhOWF9XU09tdDVKZmRhRVg4MXVrWHlrV280em5taWRoT2FMVmdkcEp6bmJCSE04aDlNbTVleGhzSndPbTJlb2RZX2U5Y1FrSEx6MFM3QklZdURUZGxPMER2NTg?oc=5) |
| Cybersecurity Dive | Microsoft SharePoint under attack via new exploit | [Source Link](https://news.google.com/rss/articles/CBMijwFBVV95cUxOQ09qMWhabGFtT05pek1CeEVjeXZ4S21QalpqOXNmTXdFODJDSTB0ZzdBb29IVjlYYk1Bc2FyMThJOE5VSVVZRDRuaGRQRU81UXZNX2V4WEYyUllKdW5UcHhjRHJLS0tzUjItZ0loRFRJa01OZTQwY1Q3b3dZN0FVMG94UzdLOExOdGZiY3oxTQ?oc=5) |
| The Hacker News | Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC | [Source Link](https://news.google.com/rss/articles/CBMigwFBVV95cUxPd20wV1l0MGlpRENiMVJKNmx1YjAtUTQ2WHl3aE0xLU4zU2h6RDl4bGRZMHU2UlM0UVRCTDdWaTh6WWxVUk9zWmtqemNZVU45Z0lFTVk0M1QxMjRCYmNpbkJOTzNrckRrakozT01IaHJyQTZKeUsyTllpT3Z6THNvRlJGSQ?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-07-21/critical-sharepoint-rce-cve-2026-50522-under-active-exploitation-after-public*
