All posts

Fourth SharePoint RCE exploited: CVE-2026-50522

The Senserva daily security read, July 22, 2026

CVE-2026-50522: fourth SharePoint RCE exploited in a month

The headline today is another exploited SharePoint Server bug. SecurityWeek and Help Net Security both report CVE-2026-50522 is being used in the wild, the fourth SharePoint vulnerability abused in the past month's wave of attacks. BleepingComputer describes the pattern plainly: attackers exploit the flaw to steal machine keys off the server.

That machine key theft is the part that turns a single patch into a bigger job. Stolen ASP.NET machine keys let an attacker forge authentication and stay in even after you patch. Help Net Security spells it out in their title: patch, then rotate your machine keys. CERT-EU has also published advisory 2026-009 on the critical SharePoint issue.

If you run on-premises SharePoint, treat this as patch now and then rotate keys, not patch eventually. Check for signs of prior exploitation before you assume the update closed the door.

KEV additions on July 21: Langflow, WordPress, DD-WRT

CISA added four flaws to the Known Exploited Vulnerabilities catalog on 2026-07-21. Two are WordPress Core: CVE-2026-63030, an interpretation conflict rated CVSS 9.8, and CVE-2026-60137, a SQL injection. These are the wp2shell chain that BleepingComputer, Dark Reading, Tenable, and SANS ISC all covered over the weekend, with active exploitation confirmed to install webshells on WordPress sites. SANS ISC reported exploitation underway as of July 20.

Also added: CVE-2026-0770, a Langflow flaw at CVSS 9.8, alongside a related Langflow authorization bypass, CVE-2026-55255, still ranking high on the mover list. BleepingComputer notes CISA has ordered federal agencies to patch the actively exploited Langflow RCE. The fourth KEV add is CVE-2021-27137, a DD-WRT stack-based buffer overflow at CVSS 8.1.

None of these are marked ransomware-linked in the data, but KEV listing means confirmed exploitation. That is your line between routine and urgent.

What else is moving

CVE-2026-48282, the Adobe ColdFusion path traversal at CVSS 10, still tops the hot list and remains KEV-listed. If you have not closed it, it stays a priority. Ubiquiti UniFi OS CVE-2026-34910, also CVSS 10 and KEV-listed, sits high on the movers with an EPSS around 0.79.

On the ransomware front, BleepingComputer reports the Qilin gang is now exploiting a critical Palo Alto GlobalProtect VPN bug. If you run GlobalProtect, that report alone should reprioritize your queue. Separately, Qualys detailed CVE-2026-8933, a local privilege escalation in snap-confine on Linux, and BleepingComputer covered free unofficial patches for a Windows LegacyHive zero-day.

KB5094144 for Exchange Server 2019 Cumulative Update 14 is flagged as carrying KEV content across 8 CVEs, and Exchange spoofing bug CVE-2026-42897 is KEV-listed. Exchange admins should confirm that update is applied.

Do this first

A short, ordered list grounded in today's facts:

Check your own state

To confirm where you stand across all of this, the free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily so the Langflow, WordPress, and DD-WRT entries show up as they land.

If you also want to check your Microsoft 365, Intune, Defender, and Entra ID configuration, Siemserva offers three free unlimited audits of your own tenant.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-22.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.