Microsoft says Entra ID flaw exploited in wild, no user action needed
This digest was compiled by AI from multiple sources — links to the originals are below.

Microsoft warned Thursday that a maximum-severity flaw in Entra ID, CVE-2026-69836, has been exploited in the wild. The remote code execution vulnerability carries a CVSS score of 10.0. Microsoft said the issue is fully mitigated and requires no customer action.
Key Facts
- CVE-2026-69836 is a remote code execution vulnerability in Microsoft Entra ID with a CVSS score of 10.0.
- Microsoft said the flaw has been exploited in the wild but is fully mitigated, requiring no action from users.
- Principal Security Engineer Robert Fitzaptrick was credited with discovering and reporting the issue.
- Microsoft did not disclose details on how the vulnerability was exploited, when exploitation began, or whether it is ongoing.
Vulnerability Details
The flaw, tracked as CVE-2026-69836, is a case of remote code execution in Microsoft Entra ID, formerly Azure Active Directory. It stems from deserialization of untrusted data, allowing an unauthorized attacker to execute code over a network. Microsoft assigned the vulnerability a CVSS score of 10.0, the highest possible severity rating. The company credited Principal Security Engineer Robert Fitzaptrick for discovering and reporting the issue.
Exploitation and Mitigation
Microsoft warned that the flaw has been exploited in the wild, but provided no details on the attacks. The company stated that the vulnerability has already been fully mitigated and no action is required from users of the service. Earlier this month, Microsoft also patched a high-severity privilege escalation flaw in Windows Ancillary Function Driver for WinSock, CVE-2026-68820, which was exploited as a zero-day by the North Korea-linked Lazarus Group.
1 source
Microsoft says Entra ID flaw exploited in wild, no user action needed



