CISA on Tuesday formally confirmed active exploitation of CVE-2026-50522, an unauthenticated flaw that lets attackers force SharePoint to process maliciously crafted data and execute code remotely.
Microsoft released patches for the affected versions of SharePoint on July 14. But within days it became a matter of incident response, with the need to rotate keys and hunt for payloads that may have been left behind, rather than just patching. By July 20th, security group watchTowr said, it was seeing exploit attempts on its honeypots.
Based on what it observed, attackers were "pulling SharePoint machine keys via a single request," watchTowr said.