Microsoft patches critical Entra ID flaw exploited in attacks
This digest was compiled by AI from multiple sources — links to the originals are below.

Microsoft has patched a maximum-severity vulnerability in its Entra ID identity platform that has been exploited in attacks. The flaw, tracked as CVE-2026-69836, allowed unauthorized attackers to execute code over a network without privileges. Microsoft says the vulnerability is fully mitigated and no user action is required.
Key Facts
- Microsoft patched CVE-2026-69836, a critical Entra ID flaw that allowed unauthorized code execution over a network.
- The vulnerability was discovered by Microsoft principal security engineer Robert Fitzpatrick.
- Microsoft says exploit code for CVE-2026-69836 is not yet available online and no user action is needed.
- On the same day, Microsoft addressed four other maximum severity flaws affecting Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra.
- CISA tagged a critical remote code execution flaw in Windows IKE Service Extensions as actively exploited on Friday.
Entra ID Vulnerability
Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management platform that has been exploited in attacks. Tracked as CVE-2026-69836, the flaw allowed threat actors with no privileges to gain code execution in low-complexity attacks. Microsoft principal security engineer Robert Fitzpatrick discovered the vulnerability. Microsoft stated that deserialization of untrusted data in Entra ID allowed an unauthorized attacker to execute code over a network. The company said the vulnerability has already been fully mitigated and no action is required from users.
Related Microsoft Patches
On the same day, Microsoft addressed four more maximum severity flaws. Three of those flaws allowed unauthenticated attackers to escalate privileges remotely on Azure Arc and Exchange Online. The fourth flaw enabled remote code execution on an Azure Managed Instance for Apache Cassandra. In September 2025, Microsoft patched another critical Entra ID privilege escalation flaw reported by security researcher Dirk-jan Mollema.
Active Exploitation Alerts
CISA tagged a critical-severity remote code execution flaw in the Windows Internet Key Exchange Service Extensions component as actively exploited on Friday. Microsoft did not share additional information about attacks exploiting CVE-2026-69836. A Microsoft spokesperson was not immediately available for comment.
2 sources
Microsoft patches critical Entra ID flaw exploited in attacks






