ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Microsoft patches critical Entra ID vulnerability (CVE-2026-69836)

AI summary · glm-5.3-flash

Microsoft patched critical Entra ID RCE CVE-2026-69836 (CVSS 10.0), fully mitigated server-side with no customer action; no in-the-wild exploitation confirmed.

Microsoft patched CVE-2026-69836, a critical (maximum CVSS 10.0) unauthenticated remote code execution flaw in Entra ID caused by deserialization of untrusted data over a network. Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service verifying logins and controlling access to Microsoft 365, Azure, and connected third-party apps. The flaw was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and fully mitigated server-side, requiring no customer action. Microsoft initially reported the bug as exploited, but later changed the status to 'no' and confirmed the vulnerability was not exploited in the wild.

  • Unauthenticated RCE via deserialization of untrusted data in Microsoft's cloud identity service.
  • Discovered by Microsoft Principal Security Engineer Robert Fitzpatrick.
  • Fully mitigated server-side; no customer remediation required.
  • Exploitation status revised from exploited to not exploited on August 24, 2026.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-69836
Unauthenticated Deserialization RCE in Microsoft Entra ID

CVE-2026-69836 is a deserialization-of-untrusted-data flaw (CWE-502) in Microsoft Entra ID, Microsoft's cloud identity and access management service. An unauthenticated attacker can trigger it by sending crafted serialized data over the network, and the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) confirms that no privileges or user interaction are required. Successful exploitation yields remote code execution with high impact to confidentiality, integrity, and availability, and the changed-scope rating indicates impact can extend beyond the initially affected component. Any organization whose sign-in or identity infrastructure relies on Microsoft Entra ID is potentially in scope, although the source data publishes no specific affected version ranges. There is no known public proof-of-concept, the flaw is not in CISA's KEV, EPSS assigns a 1.6% probability of exploitation within 30 days, and related headlines indicate Microsoft has already patched the issue.

Do: Because Entra ID is a Microsoft-operated cloud service, there is no on-premises patch to apply; consult Microsoft's advisory to confirm the fix has rolled out to your tenant and whether any tenant-level action is required. Review Entra ID sign-in logs, audit logs, and application registrations for anomalies consistent with pre-authentication exploitation, and monitor Microsoft's advisory and CISA KEV for status changes.

10.02%
  • Microsoft Entra ID
masshundreds of millions of users across effectively all Microsoft 365/Azure tenants (on the order of millions of organizations)
Full article236 words · extracted from helpnetsecurity.com · click to collapse

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, initially reported to have been exploited in the wild.

Microsoft Entra ID vulnerability CVE-2026-69836

Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps.

Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and could allow an unauthenticated attacker to remotely execute code in Microsoft’s cloud identity service.

“Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft’s advisory says.

The good news for administrators is that this CVE requires no customer action.

“This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency,” the company noted.

UPDATE (August 24, 2026, 02:15 a.m. ET):

When Microsoft published the CVE-2026-69836 advisory, it stated that the bug was exploited.

Since then, the company changed the exploitation status to “no” and confirmed to Help Net Security that the vulnerability was not exploited in the wild. This article and its headline have been modified to reflect this update.

“We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take,” a company spokesperson stated.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/21/microsoft-entra-id-vulnerability-cve-2026-69836/