GCS Threat Briefing
Threat Landscape

Patched but Still Compromised

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
July 2026 · 6 min read
GCS Threat Briefing: Patched but Still Compromised. Dark graphic reading Patched does not equal safe, covering SharePoint vulnerability CVE-2026-50522 with a CVSS severity of 9.8.

A few days ago, on 25 July, CISA's remediation deadline passed for CVE-2026-50522, a critical remote code execution vulnerability in on-premises Microsoft SharePoint. Most organisations that patched it believe the matter is closed. For a significant number of them, it is not. The attacker is still inside, and the patch did nothing to remove them.

This briefing explains what happened, why this vulnerability breaks the normal remediation script, and what leadership teams should be asking their organisations this week.

What happened

The timeline tells you everything about the speed of modern exploitation. A deserialisation flaw in SharePoint was disclosed and patched by Microsoft. Public proof-of-concept exploit code was released. Within hours, security researchers at watchTowr observed active exploitation in the wild. On 22 July, CISA added the flaw to its Known Exploited Vulnerabilities catalogue and gave US federal agencies just three days to remediate, one of the tightest windows issued this year.

9.8CVSS severity score
Hoursfrom exploit code to attacks
3 daysCISA remediation window
72 hrsICO notification window
Infographic titled CVE-2026-50522 by the numbers: CVSS severity 9.8 for a critical remote code execution flaw in on-premises Microsoft SharePoint, hours from public exploit code to active exploitation, a three-day CISA remediation window for US federal agencies, and the 72-hour UK GDPR window to notify the ICO once a breach is known.
The window between public exploit code and active exploitation is now measured in hours, not weeks. If your patching cycle runs monthly, you are structurally behind the threat.

Why this one is different

Most vulnerabilities follow a familiar script: patch quickly and the risk is closed. CVE-2026-50522 breaks that script.

Attackers exploiting this flaw are stealing SharePoint machine keys in a single request. These cryptographic keys let an attacker forge trusted payloads to the server, which means they retain access even after the patch is applied.

Read that again, because it is the entire story: patching does not evict the attacker.

An organisation that patched promptly, closed the ticket and reported "remediated" to the board may still be fully compromised. Genuine remediation here has three parts: patch the affected SharePoint servers, rotate machine keys to invalidate anything the attacker exfiltrated, and hunt for persistence, meaning webshells, forged tokens and lateral movement established before the patch landed.

Most IT teams did step one. Far fewer did steps two and three. That delta, between "patched" and "safe", is where the real business risk sits today.

Infographic titled Patched is not safe, showing the three-step response to CVE-2026-50522: one, patch to close the door by applying the SharePoint fix immediately; two, rotate keys to invalidate stolen machine keys; three, hunt to verify no persistence such as webshells, forged tokens or lateral movement. Most teams stopped at step one.
Remediation is a process, not a patch. The full response: patch, rotate machine keys, hunt for persistence.

It was not an isolated incident

The same week, Check Point disclosed CVE-2026-16232, a critical authentication bypass in SmartConsole, the management interface for its security platform, also under active exploitation. An unauthenticated attacker could obtain a login token and take full administrative control of the security management server: the console that governs the firewall estate.

Two lessons compound here. First, the security stack itself is now a primary attack surface. "We have a firewall" is not a control if the firewall's management plane can be hijacked. Second, both incidents demand the same discipline: patching plus credential and key rotation plus verification.

The commercial exposure for UK organisations

On-premises SharePoint remains deeply embedded across the UK mid-market, professional services and public sector, often as legacy infrastructure with unclear ownership. That is precisely where silent persistence thrives. The exposure is commercial, not just technical.

Regulatory. Undetected persistence means undetected data access. UK GDPR requires ICO notification within 72 hours of becoming aware of a qualifying breach, and "we patched in July but discovered the intrusion in November" is a very uncomfortable disclosure narrative. The incoming Cyber Security & Resilience Bill will tighten reporting duties further, with 24-hour early alerts and 72-hour full reports for in-scope organisations.

Financial. Incident response costs scale with dwell time. An attacker discovered after four months of quiet access costs a multiple of one discovered in four days.

Contractual and reputational. Enterprise clients increasingly require evidence of vulnerability and incident management maturity. A persistence event discovered late can put contracts, renewals and insurance cover at risk.

Governance. If the board has been told "remediated" when the true state is "patched but unverified", leadership is carrying risk it does not know it owns.

The strategic takeaway for leadership

This event is a case study in the difference between vulnerability management, which closes tickets, and risk management, which verifies the business is actually safe. Three questions for your team this week:

1. Do we run on-prem SharePoint anywhere, including the legacy instance nobody owns, across subsidiaries and acquisitions?

2. Did we rotate machine keys, or just patch? Patch, rotate and hunt should be the default playbook for any actively exploited flaw, not the exception.

3. Have we actively hunted for persistence since the exploit went public? If public exploit code to exploitation is now hours, is our emergency response built for hours?

Infographic titled Three questions for your team this week: one, do we run on-premises SharePoint anywhere including the legacy instance nobody owns; two, did we rotate machine keys or just patch; three, have we actively hunted for persistence since the exploit went public. If the answer is not sure, that is not a technical gap, it is a governance gap.
If the answer to any of these is "not sure", that is not a technical gap. It is a governance gap.

Organisations that treat moments like this as governance triggers, not IT noise, consistently spend less on incidents and win more enterprise trust. Security maturity is a commercial asset: it shortens procurement cycles, protects margin and keeps regulators at arm's length.

At Garzon Cyber Solutions, this is the gap we close for founders, CISOs and CTOs across the UK, EU and Americas: the distance between what IT reports and what the business is actually exposed to. If you run on-premises SharePoint, or you are not certain whether you do, that uncertainty is the finding.

Was your remediation verified, or just assumed?

A focused discussion about your exposure, whether machine keys were rotated, and whether anyone has actually hunted for persistence.

Discuss More →

Sources: CISA Known Exploited Vulnerabilities catalogue; watchTowr research on active exploitation of CVE-2026-50522; Rapid7 analysis of CVE-2026-16232; The Hacker News reporting, July 2026. GCS Threat Briefings translate emerging threat intelligence into the commercial and operational decisions that boards and security leaders need to make.

#Cybersecurity #SharePoint #ThreatIntelligence #IncidentResponse #RiskManagement #CISO #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability for organisations scaling into enterprise markets.