Filed under: Cybersecurity — Patching & Ransomware — July 2026
What happened
Microsoft’s July Patch Tuesday fixed a critical flaw in on-premises SharePoint Server (CVE-2026-50522), but within days a public proof-of-concept leaked and attackers started using it for real. The bug lets an authenticated site user run their own code on the server, and once in, attackers are stealing the server’s cryptographic “machine keys” so they can keep quiet, persistent access even after the server is patched.
Why it matters to your business
This only applies if your business (or a vendor you use) hosts its own SharePoint server on-site rather than using SharePoint Online inside Microsoft 365 — but if that’s you, this is a serious problem. This is the second on-prem SharePoint crisis this year, and the stolen-key trick means a server that gets patched today could still have a hidden backdoor left over from before the patch. That’s exactly the kind of quiet foothold ransomware crews use to sit inside a network for weeks before pulling the trigger.
What to do this week
If you have an on-prem SharePoint Server (Subscription Edition, 2019, or 2016), confirm the July 2026 security update is installed — check Central Administration > Upgrade and Migration > Check Product and Patch Installation Status. Because attackers may have already stolen machine keys before you patched, don’t stop there: rotate the ASP.NET machine keys and recycle the IIS application pools afterward, and have someone check IIS logs for unfamiliar w3wp.exe child processes or unexpected DLLs. If any of this is unfamiliar, treat it as a “stop and call someone” moment rather than a DIY afternoon.
The bigger picture
On-prem SharePoint has now had two actively-exploited critical bugs in a single year, and each one requires this same scramble of patch-plus-key-rotation. For most small businesses, moving that workload to SharePoint Online removes this recurring fire drill entirely. — Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
Not sure if your file server setup is exposed to this? Book a free consult — https://micro1tech.com/contact/