Microsoft patches critical Entra ID flaw exploited in the wild
This digest was compiled by AI from multiple sources — links to the originals are below.

Microsoft patched a critical remote code execution vulnerability in Entra ID, tracked as CVE-2026-69836, that was exploited in the wild. The flaw carried a maximum CVSS score of 10.0 and required no customer action because Microsoft fully mitigated it. Microsoft has not disclosed who exploited the flaw, when attacks began, or how many organizations were affected.
Key Facts
- CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID with a CVSS score of 10.0.
- The vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick.
- Microsoft stated the vulnerability has already been fully mitigated and requires no action from users.
- Microsoft has not disclosed the attackers, the start date of exploitation, the number of affected organizations, or the actions taken by attackers.
Vulnerability Details
CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID, Microsoft's cloud identity service formerly known as Azure Active Directory. The flaw allowed an unauthenticated attacker to remotely execute code over a network, according to Microsoft's advisory. Microsoft assigned the vulnerability a maximum CVSS score of 10.0. Microsoft Principal Security Engineer Robert Fitzpatrick discovered the vulnerability.
Exploitation and Response
Microsoft confirmed the vulnerability was exploited in the wild. The company has not disclosed who was behind the exploitation, when it started, how many organizations were affected, or what attackers did once inside the vulnerable service. Microsoft stated the vulnerability has already been fully mitigated and no action is required from users of the service. The CVE was published to provide further transparency, according to Microsoft.
1 source
Microsoft patches critical Entra ID flaw exploited in the wild






