Microsoft patches critical Entra ID flaw after detecting active exploitation
Microsoft confirmed that a CVSS-10 vulnerability in its Entra ID cloud-identity service was being exploited in the wild and has now been fully mitigated.
A maximum-severity vulnerability in Microsoft’s Entra ID identity platform, identified as CVE-2026-69836, was found to be actively exploited before the company issued a fix. The bug stemmed from unsafe deserialization, enabling an unauthenticated attacker to run code over the network without any user interaction. Microsoft announced the flaw on Thursday, noting that exploitation had already been detected, but withheld details about the attackers or the extent of compromise.
The cloud-based service was patched on Microsoft’s side, so no customer-installed update is needed. The company highlighted that the issue has been fully mitigated and credited principal security engineer Robert Fitzpatrick for the discovery and reporting of the vulnerability.
Why it matters
A perfect-score cloud-identity bug could have exposed countless corporate accounts, but Microsoft’s swift remediation prevented further damage.
In this story
