CVE-2026-41103Patch(microsoft / confluence_saml_sso)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch microsoft confluence_saml_sso systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a network.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-303

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confluence_saml_sso
  • jira_saml_sso

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 16 mentions across 5 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 9 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 8 mentions (2026-05-13); latest day: 1
  • 16 total mentions across 5 days

Affected systems

Vendors
Products
confluence_saml_ssojira_saml_sso

Deep dive

Activity timeline16 mentions / 5d
02468Mentions · 2026-05-12: 3Mentions · 2026-05-13: 8Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Mentions · 2026-05-25: 1PoC Mentioned / Linked · 2026-05-13: 1Active Exploitation · 2026-05-13: 2Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 6Patch / Workaround · 2026-05-14: 3Patch / Workaround · 2026-05-15: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 705-1205-1305-1405-1505-25
Signal classification4 categories
Patch
1062.5%
General
318.8%
Disclosure
212.5%
Active Exploitation
16.3%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-05-123
Disclosure2Patch1
2026-05-138
Active Exploitation1General2Patch5
2026-05-143
Patch3
2026-05-151
Patch1
2026-05-251
General1
Full discourse16 posts
  • Juan Carlos Ortiz 🛡️ Ciberseguridad para Empresas@CycuraMX
    Patch

    🛡️Llegaron las actualizaciones de Windows Microsoft corrigió 138 vulnerabilidades en Windows, Office, Edge, Azure, Teams, Dynamics y otros productos. Las más urgentes para muchas empresas son: CVE-2026-41096, en Windows DNS. DNS traduce nombres como “empresa punto com” a direcciones que entienden los sistemas. Esta falla podría permitir ejecutar código remoto sin autenticación. CVE-2026-41089, en Windows Netlogon. Netlogon ayuda a validar usuarios en servidores de dominio. Si se explota, un atacante podría ejecutar código contra un controlador de dominio. CVE-2026-42898, en Dynamics 365 local. Dynamics administra ventas, clientes y operaciones. Esta falla puede convertir una aplicación de negocio en punto de ejecución remota. CVE-2026-41103, en el plugin SSO para Jira y Confluence. SSO permite entrar con una sola identidad. Esta falla podría permitir suplantar usuarios válidos. CVE-2026-40402, en Hyper-V. Hyper-V permite correr servidores virtuales. Esta falla podría dar privilegios altos sobre el ambiente de virtualización. Microsoft también pidió actualizar certificados de Secure Boot antes del 26 de junio de 2026. Secure Boot valida que el equipo arranque con componentes confiables.

    Post summary

    Microsoft issued updates fixing 138 vulnerabilities, including several CVEs that could enable remote code execution, and urged users to apply patches and refresh Secure Boot certificates by June 26, 2026.

    01203042.5K
    7.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers chaining CVE-2026-41089 and CVE-2026-41103 to move from Windows Netlogon compromise to Jira/Confluence takeover. The attack path demonstrates how SSO plugin vulnerabilities enable broad lateral movement across development infrastructure. Runtime segmentation helps contain such multi-stage pivoting. #ThreatIntel 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/microsoft-may-2026-patch-tuesday-cve-2026-41103

    Post summary

    The text reports that attackers are chaining CVE-2026-41089 and CVE-2026-41103 to move from a Windows Netlogon compromise into Jira and Confluence, demonstrating an active exploitation scenario.

    0001189
    1.9K followersView on X
  • ByteGuard@byte_guard_blog
    Patch

    Microsoft Patch Tuesday May 2026 ships 118 fixes with zero active zero-days, a rare quiet month. Sixteen vulnerabilities carry critical severity, including CVE-2026-41089, a stack-based buffer overflow in Windows Netlogon requiring no privileges or user interaction to grant SYSTEM access on domain controllers. CVE-2026-41103 also demands attention for allowing Entra ID impersonation via forged credentials. While vendors like Oracle and Mozilla accelerate release cadences following AI-assisted code audits, the immediate task remains applying these patches before the next cycle begins. #CyberSecurity #Windows

    Post summary

    Microsoft’s May 2026 Patch Tuesday issued 118 fixes, including critical CVE‑2026‑41089 and CVE‑2026‑41103, and users should promptly apply these patches before the next release.

    00020169
    16 followersView on X
  • Peter Casano@pcasano
    Patch

    Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) http://ow.ly/QSAK106yt2q https://t.co/DKvFARwbot

    Post summary

    Microsoft released its May 2026 security update, addressing CVE-2026-41103 among 118 other vulnerabilities, as part of Patch Tuesday.

    0001037
    16 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-40398 7.8 Windows リモート デスクトップ ・CVE-2026-41103 9.1 Jira と Confluence 用の Microsoft SSO プラグイン -対象外:10 件 ・CVE-2026-26129 7.5 M365 Copilot つづく…

    Post summary

    The tweet simply lists three CVE identifiers with their CVSS scores and affected components, offering no additional details on PoC, exploits, patches, or active attacks.

    10000107
    85 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-41103: Microsoft SSO Plugin for Jira and Confluence Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04hPhJQ0

    Post summary

    The text merely cites an article about CVE-2026-41103, lacking concrete details on exploitation, patches, or technical aspects.

    0000032
    31 followersView on X
  • Jass@Trej0Jass
    Patch

    Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) http://ow.ly/q6QY106yvnm https://t.co/ZRIkGbbmGt

    Post summary

    The tweet announces that Microsoft’s May 2026 Patch Tuesday includes a fix for CVE‑2026‑41103 among 118 other vulnerabilities, but provides no further technical or exploit details.

    0000037
    13 followersView on X
  • リテレールアトリエ@CreatorRuru
    Patch

    Microsoft、定例パッチで危険な脆弱性を修正(CVE-2026-41089・CVE-2026-41096・CVE-2026-41103) - 合同会社ロケットボーイズ https://rocket-boys.co.jp/security-measures-lab/microsoft-fixes-critical-flaws-cve-2026-41089/ @GoogleNewsより

    Post summary

    The tweet announces Microsoft’s regular patch addressing several high‑severity CVEs (CVE‑2026‑41089, 41096, 41103).

    00000113
    2.6K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Microsoft、定例パッチで危険な脆弱性を修正(CVE-2026-41089・CVE-2026-41096・CVE-2026-41103) https://rocket-boys.co.jp/security-measures-lab/microsoft-fixes-critical-flaws-cve-2026-41089/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Microsoft released a routine patch fixing three critical CVEs, with no indication of PoC, exploit code, or active exploitation.

    00000232
    405 followersView on X
  • Arthur Capella@Art_Capella
    Patch

    Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) http://ow.ly/Uyl8106yq7j https://t.co/DiYesb5Ivp

    Post summary

    Microsoft announced a Patch Tuesday that addresses 118 CVEs, including CVE‑2026‑41103.

    0000030
    165 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    🚨 CVE-2026-41103 (MS SSO Plugin for Jira & Confluence, CVSS 9.1): Unauth attacker forges login response → impersonates ANY user, bypasses Entra ID. Marked "exploitation more likely." Millions of Atlassian orgs exposed. Apply May Patch Tuesday NOW. #ZeroDay #Atlassian

    Post summary

    The post alerts that CVE‑2026‑41103 is a high‑severity flaw in Atlassian’s MS SSO plugin, enabling unauthenticated users to forge login tokens and impersonate any user, and urges immediate patching via May Patch Tuesday.

    0000067
    210 followersView on X
  • Cyberdark Imapct@kenebeii
    General

    【サイバーセキュリティ動向分析】 トレンドのセキュリティニュース(2026年5月現在): Microsoft May 2026 Patch Tuesday:120件以上の脆弱性修正(17 Critical含む)、ゼロデイなし。NetlogonやWord関連のRCEが目立つ。 https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2026-patch-tuesday-fixes-120-flaws-no-zero-days/ https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103 Linuxカーネル「Dirty Frag」脆弱性:暗号通信処理のLoP脆弱性、企業Linuxディストリビューションで影響拡大の懸念。 https://www.security-next.com/184228 Ivanti EPMM複数脆弱性:ゼロデイ攻撃確認済み、モバイル端末管理製品に深刻。 https://www.security-next.com/184153 Palo Alto Networks PAN-OS深刻脆弱性:すでに悪用確認、ファイアウォール対象。 https://www.security-next.com/184082 Chrome 148リリース:127件の脆弱性修正(クリティカル複数)。 https://www.security-next.com/184087 Spring Cloud Config複数脆弱性:パストラバーサルなど。 https://www.security-next.com/184099 日本国内インシデント:デンソー海外拠点不正アクセス、マネーフォワードGitHub侵害、東北大学サーバー不正アクセス、Chatworkアカウント侵害など。 https://cybersecurity-jp.com/news https://www.security-next.com/ AI活用攻撃のトレンド:AIによるエクスプロイト開発・自動化、Shadow AI、Agentic AIリスクが2026年の主要脅威として継続強調。 https://www.ibm.com/think/insights/more-2026-cyberthreat-trends https://www.sentinelone.com/cybersecurity-101/cybersecurity/cyber-security-trends/ その他注目:cPanel深刻脆弱性悪用、Android近接RCEなど。 https://www.darkreading.com/latest-news これらは直近のヘッドライン中心。詳細は各URLで確認を。 各脆弱性のCVE詳細を確認する ゼロデイ攻撃の検知手法 URLのリストを箇条書きで整理する

    Post summary

    The post summarizes recent CVE updates, noting available patches, active exploitation of high‑profile flaws, and providing broad technical descriptors across multiple products.

    0000044
    182 followersView on X
  • ZeroDayFacts@ZeroDayFacts
    Patch

    Microsoft May 2026 Patches 137 Vulnerabilities yesterday. None exploited in the wild yet, but ~12 rated “exploitation more likely.” Critical highlights are as under :- Microsoft SSO Plugin for Jira/Confluence (CVE-2026-41103) High-severity RCEs in Word (preview pane exploit possible) Fixes for Azure, Dynamics 365, Windows Netlogon, DNS & Hyper-V #PatchTuesday #Microsoft #CyberSecurity

    Post summary

    Microsoft's Patch Tuesday update for May 2026 covered 137 CVEs, including a high-severity RCE in Microsoft Word and CVE-2026-41103 for the Jira SSO Plugin, with no reported wild exploitation yet.

    0000074
    14 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-41103 Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a ne… https://www.cve.org/CVERecord?id=CVE-2026-41103 ----- Traducción: CVE-2026-41103 Impleme… http://infoflow.cloud`

    Post summary

    A newly disclosed vulnerability (CVE‑2026‑41103) in the Microsoft SSO Plugin for Jira & Confluence can allow an unauthenticated attacker to elevate privileges due to faulty authentication algorithm implementation. No exploit code, patch, or active exploitation details are mentioned.

    0000042
    77 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41103 Incorrect implementation of authentication algorithm in Microsoft SSO Plugin for Jira & Confluence allows an unauthorized attacker to elevate privileges over a ne… https://www.cve.org/CVERecord?id=CVE-2026-41103

    Post summary

    The post announces CVE‑2026‑41103, noting a flawed authentication algorithm in Microsoft’s SSO plugin for Jira & Confluence that could enable unauthorized privilege escalation.

    00000357
    57.5K followersView on X
  • Daniel Sant'Anna@dansantanna
    Patch

    Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) http://ow.ly/ZS3X106ynOV https://t.co/p8ZSZkfJpV

    Post summary

    The tweet announces that CVE-2026-41103 is included in Microsoft’s May 2026 Patch Tuesday release, but does not provide technical details or exploit information.

    0000045
    512 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftconfluence_saml_sso---
Appmicrosoftjira_saml_sso---

Explore more