Active Exploitation of SharePoint RCE (CVE‑2026‑50522) Enables IIS Machine‑Key Theft
What It Is — A critical remote‑code‑execution flaw in on‑premises Microsoft SharePoint (CVE‑2026‑50522) allows unauthenticated attackers to execute code on the web server and extract the IIS machine keys used for encryption and authentication.
Exploitability — Public proof‑of‑concept code released on July 20 2026; WatchTowr’s honeypot network recorded successful exploitation attempts within hours. No public exploit‑as‑a‑service, but active exploitation is confirmed. CVSS ≈ 9.8 (Critical).
Affected Products — Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on‑premises deployments).
Why It Matters for Compliance & Audit Readiness
- Control Mapping: The vulnerability bypasses the “Encrypt Data at Rest” control (SOC 2 CC6.1). Mapping this gap and evidencing remediation is essential for a defensible audit trail.
- Continuous Evidence: Rotating IIS machine keys after patching generates audit‑ready logs; without systematic collection, organizations cannot prove timely remediation.
- Enterprise Trust: Many buyers now require proof that critical infrastructure is continuously monitored and hardened, a core SOC 2 requirement.
Recommended Actions
- Apply Microsoft’s security update for CVE‑2026‑50522 immediately.
- Verify that Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application and monitor alerts.
- Rotate IIS machine keys on all affected servers and retain the rotation logs as audit evidence.
- Conduct a post‑patch hardening review (disable unnecessary services, enforce least‑privilege access).
- Implement continuous control monitoring to capture patch status, key‑rotation events, and any intrusion artifacts.
Source: Help Net Security – SharePoint RCE Exploited (CVE‑2026‑50522)