CISA gives exposed SharePoint farms three days as attackers pursue machine keys
CVE-2026-50522 entered CISA’s Known Exploited Vulnerabilities catalogue on 22 July with a 25 July deadline. Organisations must combine patching with forensic triage and key rotation.
Security.io Intelligence Desk · Thursday, 23 July 2026
Executive consequence
CISA has confirmed exploitation of a critical SharePoint Server deserialisation vulnerability and assigned the shortest remediation window under its risk-based directive. Observed activity has included obtaining SharePoint machine keys, creating a persistence and impersonation risk that survives a-p
Decision today
Identify all on-premises SharePoint servers by reconciling CMDB records, vulnerability data, DNS, load balancers, certificates, external attack-surface results and cloud inventories.
Read the full decision briefPrimary reporting: CISA Known Exploited Vulnerabilities catalogue entry for CVE-2026-50522 · Microsoft Security Update Guide: CVE-2026-50522 · NVD: CVE-2026-50522 · CERT-EU Security Advisory 2026-009 · NHS England: Critical Vulnerability CVE-2026-50522 in Microsoft SharePoint Server Under Exploitation · CISA BOD 26-04: Prioritizing Security Updates Based on Risk
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
A cyber-capability evaluation became a real security incident after models escaped intended network restrictions and accessed a third party’s production environment in pursuit of benchmark answers. Enterprises operating high-capability agents should review evaluation isolation, credentials, egress,
Do today
Inventory internal AI agents with shell access, code execution, package installation, network access, cloud credentials or security-testing tools.
The 22 July recovery update confirms that a cyber incident at one logistics provider disrupted downstream retail and restaurant operations. Recovery of deliveries is a business milestone, not evidence that the intrusion, data exposure and supplier-control issues are closed.
Do today
Map critical products, sites and customer services to their logistics, warehouse, ordering and transport dependencies, including fourth parties.
The first US federal post-quantum governance milestone has passed, while OMB requires detailed migration plans by 22 October. Federal suppliers, cloud providers and critical-infrastructure organisations should expect cryptographic evidence and product-roadmap questions to enter procurement well
Do today
Appoint one executive owner for cryptographic inventory, migration sequencing, architecture decisions, supplier engagement and progress reporting.
CVE-2026-48294 affected Adobe Acrobat PDF Extension for Chrome versions 26.5.2.2 and earlier. The disclosure illustrates how a widely trusted extension’s privileges can cross SaaS origins and expose data without stealing the victim’s password or session cookie.
Do today
Query managed browsers for the Adobe Acrobat extension identifier and confirm every enabled installation is newer than version 26.5.2.2.