Active exploitation of remote code execution bug CVE-2026-50522 is underway, and patching alone may not be enough to stop it.