DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:03:37ZSOURCES: 14CRITICAL: 15
⚠ ACTIVE ALERTS
SYLVANITE CRITICAL — SYLVANITE is a newly named Dragos-tracked threat group identified as a dedicated… /// @MsftSecIntel CRITICAL — We are tracking TeamPCP (UNC6780) activity following the GitHub internal repository… /// @GossiTheDog CRITICAL — The GitHub / TeamPCP breach is now being monetized on BreachForums. Listing is up — $95k… /// @struppigel CRITICAL — SUPPLY CHAIN ALERT: Laravel-Lang PHP packages backdoored May 22-23 via hijacked GitHub… /// @MalwareHunterTeam CRITICAL — Seeing fresh DebugElevator stealer log batches already appearing for sale on Exploit.in —…
15Critical Threats
8Active CVEs
0IOCs Tracked
0New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-41103PUBLISHED: 2026-05-12
CRITICALCVE-2026-41103

Microsoft SSO Plugin for Jira & Confluence Privilege Escalation / Identity Forgery

VENDOR: Microsoft//PRODUCT: Microsoft Single Sign-On (SSO) Plugin for Jira & Confluence
9.1
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An incorrect implementation of the authentication algorithm in the Microsoft SSO Plugin for Jira & Confluence allows an unauthenticated remote attacker to forge an SSO response during the login process and sign in as an arbitrary existing user without valid Microsoft Entra ID authentication. Successful exploitation grants the attacker full access to the victim's Jira and Confluence data and the ability to perform all actions permitted for that account. Microsoft flags this as 'Exploitation More Likely' — the only CVSS 9+ flaw in May 2026 Patch Tuesday with that rating — making it the most immediately dangerous exploitability-wise among this month's Patch Tuesday disclosures for organizations running self-hosted Atlassian instances with Microsoft Entra integration.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:N
AFFECTED VERSIONSMicrosoft SSO Plugin for Jira & Confluence all versions prior to May 2026 update
  • Microsoft MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41103
  • Security Boulevard: https://securityboulevard.com/2026/05/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103/
  • Rapid7 Patch Tuesday Blog: https://www.rapid7.com/blog/post/em-patch-tuesday-may-2026/
  • The Hacker News: https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html
  • SC World: https://www.scworld.com/news/patch-tuesday-no-zero-days-among-137-microsoft-cves-4-word-rces
SHARE BRIEF:✕ Post on Xin Share on LinkedIn