CVE-2026-50522 SharePoint RCE: Patching Isn’t Enough

CVE-2026-50522 SharePoint RCE

CVE-2026-50522 SharePoint RCE is now the third actively exploited remote code execution flaw hitting Microsoft’s on-premises collaboration platform in three weeks — and this one lets attackers steal cryptographic machine keys that remain valid long after the server is patched. If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, patching is no longer…

Read More

SharePoint RCE CVE-2026-45659: Active Exploits

SharePoint RCE CVE-2026-45659

SharePoint RCE CVE-2026-45659 is now under active exploitation, and the federal patch deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is July 4 — tomorrow. The CVSS 8.8 deserialization flaw lets any authenticated user with nothing more than baseline Site Member permissions run code remotely on the server. Shadowserver currently counts more…

Read More

PTC Windchill RCE CVE-2026-12569: Web Shells Actively Deployed

The PTC Windchill RCE CVE-2026-12569 (CVSS 9.3) is actively exploited — and this is the second attack wave targeting the same product in three months. Attackers are deploying persistent JSP web shells inside Windchill PDMLink and FlexPLM installations right now. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, 2026; the…

Read More