Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Abinaya
5 hours ago
5 Visninger
0 Kommentarer
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The attack combines an authentication bypass tracked as 78 with a remote code execution flaw, CVE-2026-63520. CVE-2026-55040, rated 9.1 out of 10 under CVSS v3.1, affects SharePoint’s JSON Web Token, or JWT, authentication handler. The flaw allows an unauthenticated attacker to forge a token and impersonate a SharePoint user if they know that user’s security identifier or user principal name, such as user@domain. The issue exists because multiple JWT security checks in SharePoint’s token validation process were disabled or insufficient. Rapid7 researchers found that the...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!