The in-the-wild exploitation of four Microsoft SharePoint vulnerabilities has come to light in the past month.

watchTowr reports active exploitation of SharePoint CVE-2026-50522 after a public PoC, with attackers stealing machine keys for persistence.

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.