CVE-2026-50522: fourth SharePoint RCE exploited in a month
The headline today is another exploited SharePoint Server bug. SecurityWeek and Help Net Security both report CVE-2026-50522 is being used in the wild, the fourth SharePoint vulnerability abused in the past month's wave of attacks. BleepingComputer describes the pattern plainly: attackers exploit the flaw to steal machine keys off the server.
That machine key theft is the part that turns a single patch into a bigger job. Stolen ASP.NET machine keys let an attacker forge authentication and stay in even after you patch. Help Net Security spells it out in their title: patch, then rotate your machine keys. CERT-EU has also published advisory 2026-009 on the critical SharePoint issue.
If you run on-premises SharePoint, treat this as patch now and then rotate keys, not patch eventually. Check for signs of prior exploitation before you assume the update closed the door.
KEV additions on July 21: Langflow, WordPress, DD-WRT
CISA added four flaws to the Known Exploited Vulnerabilities catalog on 2026-07-21. Two are WordPress Core: CVE-2026-63030, an interpretation conflict rated CVSS 9.8, and CVE-2026-60137, a SQL injection. These are the wp2shell chain that BleepingComputer, Dark Reading, Tenable, and SANS ISC all covered over the weekend, with active exploitation confirmed to install webshells on WordPress sites. SANS ISC reported exploitation underway as of July 20.
Also added: CVE-2026-0770, a Langflow flaw at CVSS 9.8, alongside a related Langflow authorization bypass, CVE-2026-55255, still ranking high on the mover list. BleepingComputer notes CISA has ordered federal agencies to patch the actively exploited Langflow RCE. The fourth KEV add is CVE-2021-27137, a DD-WRT stack-based buffer overflow at CVSS 8.1.
None of these are marked ransomware-linked in the data, but KEV listing means confirmed exploitation. That is your line between routine and urgent.
What else is moving
CVE-2026-48282, the Adobe ColdFusion path traversal at CVSS 10, still tops the hot list and remains KEV-listed. If you have not closed it, it stays a priority. Ubiquiti UniFi OS CVE-2026-34910, also CVSS 10 and KEV-listed, sits high on the movers with an EPSS around 0.79.
On the ransomware front, BleepingComputer reports the Qilin gang is now exploiting a critical Palo Alto GlobalProtect VPN bug. If you run GlobalProtect, that report alone should reprioritize your queue. Separately, Qualys detailed CVE-2026-8933, a local privilege escalation in snap-confine on Linux, and BleepingComputer covered free unofficial patches for a Windows LegacyHive zero-day.
KB5094144 for Exchange Server 2019 Cumulative Update 14 is flagged as carrying KEV content across 8 CVEs, and Exchange spoofing bug CVE-2026-42897 is KEV-listed. Exchange admins should confirm that update is applied.
Do this first
A short, ordered list grounded in today's facts:
- Patch on-premises SharePoint for CVE-2026-50522, then rotate machine keys and hunt for prior compromise.
- Patch WordPress Core for CVE-2026-63030 and CVE-2026-60137 immediately; both are KEV-listed and exploited via wp2shell.
- Update Langflow for CVE-2026-0770 and CVE-2026-55255, both actively exploited.
- Confirm Exchange KB5094144 is applied and close CVE-2026-42897.
- Review GlobalProtect exposure given active Qilin ransomware use.
- Verify ColdFusion CVE-2026-48282 and UniFi OS CVE-2026-34910 are patched.
Check your own state
To confirm where you stand across all of this, the free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker follows KEV additions daily so the Langflow, WordPress, and DD-WRT entries show up as they land.
If you also want to check your Microsoft 365, Intune, Defender, and Entra ID configuration, Siemserva offers three free unlimited audits of your own tenant.
Sources
- SecurityWeek: Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks (2026-07-22)
- Help Net Security: Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) (2026-07-22)
- BleepingComputer: CISA orders urgent action on actively exploited Langflow RCE flaw (2026-07-22)
- BleepingComputer: Critical Palo Alto VPN bug now exploited by Qilin ransomware gang (2026-07-21)
- BleepingComputer: Critical wp2shell WordPress flaws exploited to install webshells (2026-07-21)
- BleepingComputer: Critical SharePoint RCE flaw exploited to steal machine keys (2026-07-21)
- CERT-EU: 2026-009: Critical Vulnerability in Microsoft SharePoint (2026-07-22)
- SANS ISC: WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) (2026-07-20)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-22.