Kryptovalutaticker:
sysadmin från Cyber Security News

Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Abinaya
5 hours ago
6 Visningar
0 Kommentarer
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password

Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The attack combines an authentication bypass tracked as 78 with a remote code execution flaw, CVE-2026-63520. CVE-2026-55040, rated 9.1 out of 10 under CVSS v3.1, affects SharePoint’s JSON Web Token, or JWT, authentication handler. The flaw allows an unauthenticated attacker to forge a token and impersonate a SharePoint user if they know that user’s security identifier or user principal name, such as user@domain. The issue exists because multiple JWT security checks in SharePoint’s token validation process were disabled or insufficient. Rapid7 researchers found that the...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!