A critical SharePoint alert arrives, the update goes in, and the ticket closes. But what if an attacker entered before the lock was fixed and left with secrets that still work?
In this episode of Plaintext with Rich, Rich explains why CVE-2026-50522 is more than an ordinary patch story. The actively exploited remote code execution flaw affects on-premises Microsoft SharePoint Server, including SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. You will hear why CISA's Known Exploited Vulnerabilities catalog matters, how SharePoint machine keys can extend risk beyond the vulnerable code, and why a clean vulnerability scan cannot prove that nobody arrived earlier. Rich breaks the response into three separate jobs: patch the affected farm, hunt for signs of compromise and persistence, and rotate machine keys, credentials, or tokens that may have been exposed. He also explains why rotation must be coordinated to avoid session, authentication, and integration problems.
This episode is for leaders, business owners, IT teams, and anyone responsible for asking whether a SharePoint incident is truly contained. It gives you better questions for the status meeting without turning a serious risk into panic.
YouTube more your speed? → https://links.sith2.com/YouTube Apple Podcasts your usual stop? → https://links.sith2.com/Apple Neither of those? Spotify’s over here → https://links.sith2.com/Spotify Prefer reading quietly at your own pace? → https://links.sith2.com/Blog Join us in The Cyber Sanctuary (no robes required) → https://links.sith2.com/Discord Follow the human behind the microphone → https://links.sith2.com/linkedin Need another way to reach me? That’s here → https://linktr.ee/rich.greene
Podden och tillhörande omslagsbild på den här sidan tillhör
Rich Greene. Innehållet i podden är skapat av Rich Greene och inte av,
eller tillsammans med, Poddtoppen.