TGViewer
Security Analysis Security Analysis @securation · 12.3K subscribers
Post #1958 4.17K
⭕️ در جریان یک پروژه تحقیقاتی روی آسیب‌پذیری‌های 0day در SharePoint، تیم Rapid7 Labs دو آسیب‌پذیری جدید را کشف کرد که با chain آن‌ها می‌توان روی یک سرور آسیب‌پذیر، RCE به دست آورد.
امروز Rapid7 و Microsoft نخستین آسیب‌پذیری این زنجیره را با شناسه CVE-2026-55040 منتشر کردند.
این نقص، امکان دور زدن احراز هویت مبتنی بر توکن JWT در Microsoft SharePoint را فراهم می‌کند.

https://www.rapid7.com/blog/post/ve-cve-2026-55040-microsoft-sharepoint-jwt-token-authentication-bypass-fixed/⁠
#JWT #Sharepoint #Rapid7
@securation
Rapid7 CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED) Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of 2 new vulnerabilities that – when chained together – achieve unauthenticated remote code execution against a vulnerable SharePoint server. More in…
  • 👍 8
  • ❤ 2
More from @securation
  1. Sep 28, 2026ترس توی ذهن آدم با فکر کردن بزرگتر میشه. اما وقتی دست به اقدام میزنی کوچیکتر میشه. @secura…
  2. Sep 27, 2026⭕️مهندسی معکوس و دور زدن محدودیت‌های نرم‌افزاری با OpenClaw و Codex این منابع راهنمای جامع…
  3. Sep 25, 2026⭕️نقش AI در جاهای کاربردی اینشکلی هست که الان بعنوان مثال اوبونتو به انتشار هفتگی به‌روزرس…
  4. Sep 23, 2026خبر خوب اول مهر اینکه یک زیرودی به اپل گزارش داده بودم ، فیکس کردن و گزارش رو هم بدون تشکر…
  5. Sep 22, 2026⭕️ گروه هکری "شاینی هانترز" ادعا کرده است که به سیستم‌های اداره تحقیقات فدرال (FBI) نفوذ ک…
  6. Sep 20, 2026🚀 رونمایی از تیزر رسمی رویداد «المپیک فناوری ۱۴۰۵» 🚀 Official Teaser: Tech Olympics 2026…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →