HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Active Exploitation of SharePoint RCE (CVE‑2026‑50522) Enables IIS Machine‑Key Theft

Attackers are actively exploiting CVE‑2026‑50522, a critical unauthenticated RCE in on‑premises Microsoft SharePoint, to extract IIS machine keys. The flaw underscores the need for rapid patching, key rotation, and continuous control evidence to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 helpnetsecurity.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
helpnetsecurity.com

Active Exploitation of SharePoint RCE (CVE‑2026‑50522) Enables IIS Machine‑Key Theft

What It Is — A critical remote‑code‑execution flaw in on‑premises Microsoft SharePoint (CVE‑2026‑50522) allows unauthenticated attackers to execute code on the web server and extract the IIS machine keys used for encryption and authentication.

Exploitability — Public proof‑of‑concept code released on July 20 2026; WatchTowr’s honeypot network recorded successful exploitation attempts within hours. No public exploit‑as‑a‑service, but active exploitation is confirmed. CVSS ≈ 9.8 (Critical).

Affected Products — Microsoft SharePoint Server 2016, 2019, and Subscription Edition (on‑premises deployments).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The vulnerability bypasses the “Encrypt Data at Rest” control (SOC 2 CC6.1). Mapping this gap and evidencing remediation is essential for a defensible audit trail.
  • Continuous Evidence: Rotating IIS machine keys after patching generates audit‑ready logs; without systematic collection, organizations cannot prove timely remediation.
  • Enterprise Trust: Many buyers now require proof that critical infrastructure is continuously monitored and hardened, a core SOC 2 requirement.

Recommended Actions

  • Apply Microsoft’s security update for CVE‑2026‑50522 immediately.
  • Verify that Antimalware Scan Interface (AMSI) integration is enabled for every SharePoint web application and monitor alerts.
  • Rotate IIS machine keys on all affected servers and retain the rotation logs as audit evidence.
  • Conduct a post‑patch hardening review (disable unnecessary services, enforce least‑privilege access).
  • Implement continuous control monitoring to capture patch status, key‑rotation events, and any intrusion artifacts.

Source: Help Net Security – SharePoint RCE Exploited (CVE‑2026‑50522)

📰 Original Source
https://www.helpnetsecurity.com/2026/07/22/sharepoint-cve-2026-50522-exploited/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →