Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Abinaya
5 hours ago
4 Visninger
0 Kommentarer
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The attack combines an authentication bypass tracked as 78 with a remote code execution flaw, CVE-2026-63520. CVE-2026-55040, rated 9.1 out of 10 under CVSS v3.1, affects SharePoint’s JSON Web Token, or JWT, authentication handler. The flaw allows an unauthenticated attacker to forge a token and impersonate a SharePoint user if they know that user’s security identifier or user principal name, such as user@domain. The issue exists because multiple JWT security checks in SharePoint’s token validation process were disabled or insufficient. Rapid7 researchers found that the...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!