A critical remote code execution flaw in Microsoft SharePoint, tracked as CVE-2026-50522, is being actively exploited by hackers to steal machine keys, allowing them to retain access to compromised servers even after patches are applied. This vulnerability enables attackers to execute arbitrary code on affected systems, resulting in the exfiltration of sensitive machine keys. The exploitation of this flaw is currently under discussion with Microsoft, with the status of the exploitation determining the urgency of the patch. The fact that hackers are already leveraging this vulnerability to steal machine keys highlights the severity of the issue1. As a result, practitioners should prioritize patching vulnerable SharePoint servers to prevent potential breaches. The theft of machine keys can have long-lasting consequences, including unauthorized access to sensitive data and systems, so it is crucial for organizations to address this vulnerability promptly to prevent further exploitation.