
Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password
Two serious Microsoft SharePoint Server vulnerabilities can be chained to let remote attackers take control of vulnerable servers without a password. The attack combines an authentication bypass tracked as 78 with a remote code execution flaw, CVE-2026-63520. CVE-2026-55040, rated 9.1 out of 10 under CVSS v3.1, affects SharePoint’s JSON Web Token, or JWT, authentication handler. […]
The post Two Microsoft SharePoint Flaws Can Be Chained to Hack Servers Without a Password appeared first on Cyber Security News.