CVE-2026-50522: SharePoint Deserialization RCE Now Actively Exploited (CISA KEV) — Detect Exposure and Evict Persistence
The unauthenticated SharePoint deserialization RCE demonstrated at Pwn2Own Berlin 2026 is now exploited in the wild and CISA KEV-listed with a July 25 deadline. CVSS 9.8 Critical (CWE-502), on-premises SharePoint Server only. The operational twist: attackers steal ASP.NET machine keys during exploitation, so patching closes the door but doesn't evict an intruder who already has the keys — patch, rotate keys, then hunt.