2 actively exploited SharePoint RCEs (CVE-2026-50522, CVE-2026-58644): patch, rotate keys, hunt persistence
Two unauthenticated SharePoint Server RCEs, CVE-2026-50522 and CVE-2026-58644 (both CVSS 9.8), are exploited in the wild. Patching alone will not evict an attacker who stole your machine keys.