CVE-2026-50522: Why SharePoint Patching Is Only Step One episode artwork

EPISODE · Aug 7, 2026 · 9 MIN

CVE-2026-50522: Why SharePoint Patching Is Only Step One

from Plaintext with Rich · host Rich Greene

A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work?In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. You will hear why CISA's Known Exploited Vulnerabilities catalog matters, how SharePoint machine keys can extend risk beyond the vulnerable code, and why a clean vulnerability scan cannot prove that nobody arrived earlier. Rich breaks the response into three separate jobs: patch the affected farm, hunt for signs of compromise and persistence, and rotate machine keys, credentials, or tokens that may have been exposed. He also explains why rotation must be coordinated to avoid session, authentication, and integration problems.This episode is for leaders, business owners, IT teams, and anyone responsible for asking whether a SharePoint incident is truly contained. It gives you better questions for the status meeting without turning a serious risk into panic.One Topic, Ten minutes, No panic.Is there a topic/term you want me to discuss next? Text me!!YouTube more your speed? → https://links.sith2.com/YouTube  Apple Podcasts your usual stop? → https://links.sith2.com/Apple  Neither of those? Spotify’s over here → https://links.sith2.com/Spotify  Prefer reading quietly at your own pace? → https://links.sith2.com/Blog  Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord  Follow the human behind the microphone → https://links.sith2.com/linkedin  Need another way to reach me? That’s here → https://linktr.ee/rich.greene

Episode metadata supplied by the publisher feed · Published Aug 7, 2026

Embed this episode

A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work? In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Editio...

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

CVE-2026-50522: Why SharePoint Patching Is Only Step One

0:00 9:42

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Plaintext with Rich?

This episode is 9 minutes long.

When was this Plaintext with Rich episode published?

This episode was published on August 7, 2026.

Can I download this Plaintext with Rich episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!