View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical SharePoint RCE CVE-2026-50522 exploited to steal machine keys

🚨 ACTIVE EXPLOITATION

  • Critical SharePoint RCE CVE-2026-50522 exploited to steal machine keys — BleepingComputer
    Hackers are exploiting a critical SharePoint remote code execution vulnerability to steal machine keys.
    • Applies to on-premise Microsoft SharePoint deployments vulnerable to CVE-2026-50522
    • Vulnerability is a deserialization-of-untrusted-data flaw enabling remote code execution without authentication
    • Attackers deliver malicious .NET payload via forged SecurityContextToken cookie in WS-Federation sign-in response
    • Exploitation allows stealing machine keys to create authentication tokens and maintain persistent access
    • Proof-of-concept exploit was publicly released on July 20, 2026, followed by active exploitation observed by security firms

🕵️ RESEARCH & DEEP DIVES

  • Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs — The Hacker News
    Apple patched a bug in Hide My Email that exposed users' real email addresses.
    • Applies to iCloud+ subscribers using Apple's Hide My Email feature
    • Bug exposed real email addresses behind Hide My Email aliases in mail logs
    • Exposure triggered when a message sent to a Hide My Email address was rejected as spam
    • Issue disclosed to Apple in June 2025, fixed on July 3, 2026 after multiple patch attempts
    • Emails bounced as spam could leak real addresses even if messages never reached inbox

📋 ADVISORIES

  • Oracle July 2026 CPU Fixes 1235 CVEs with 261 Critical Patches Across 32 Products — Tenable
    Oracle released its largest July 2026 Critical Patch Update addressing 1235 CVEs.
    • Applies to 32 Oracle product families including E-Business Suite, Fusion Middleware, and Communications
    • Fixes 1235 unique CVEs via 1449 security patches, with 261 critical severity issues
    • Oracle E-Business Suite received the most patches at 410 (28.3% of total)
    • Many vulnerabilities are remotely exploitable without authentication, notably in Fusion Middleware and Communications
    • Patch update released July 21, 2026, as Oracle's third quarterly CPU of the year

🔓 CVEs & KEV

  • Other: 20 CVEs (worst 9.9)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check