Microsoft has patched a critical, maximum-severity vulnerability in its Entra ID identity and access management (IAM) platform after confirming that the flaw was exploited in an attack.
Microsoft Entra ID, formerly known as Azure Active Directory (Azure AD), is a cloud-based IAM service that provides authentication, policy enforcement, and security controls for applications and resources used by Microsoft 365, Azure, and Dynamics CRM Online customers.
Tracked as CVE-2026-69836, the critical security vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick. The flaw allows an unprivileged attacker to execute code over a network using a low-complexity attack.
Microsoft said exploit code for CVE-2026-69836 has not been publicly released. The company also confirmed that the vulnerability has been fully patched and that users do not need to take any action.
“Deserialization of untrusted data in Microsoft Entra ID allows an unprivileged attacker to execute code on the network,” Microsoft said in a security advisory published Thursday.
“This vulnerability has already been fully mitigated by Microsoft. There is no action required for users of this service. The purpose of this CVE is to provide further transparency.”
Microsoft has not released additional technical details about the incident. A company spokesperson also did not immediately respond to BleepingComputer’s request for information about the attack that exploited CVE-2026-69836.
Microsoft also addressed four other maximum-severity vulnerabilities the previous day. Three of the flaws allow unauthenticated attackers to remotely escalate privileges in Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, CVE-2026-65770, is a remote code execution vulnerability affecting Azure Managed Instance for Apache Cassandra.
In September 2025, security researcher Dirk-jan Mollema of Outsider Security reported another critical Microsoft Entra ID privilege escalation vulnerability, CVE-2025-55241. The flaw reportedly allowed attackers to gain extensive access to Microsoft Entra ID tenants.
On Friday, CISA also added a high-severity remote code execution (RCE) vulnerability affecting the Windows Internet Key Exchange (IKE) Service Extensions component to its list of flaws being actively exploited.
The overall prevention score can obscure what happens after an attacker gains initial access. If threat actors use valid credentials, the effectiveness of your defenses can drop sharply.
Blue Report 2026 measures defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




