Published on August 21, 2026
[CVE-2026-69836] Critical Microsoft Entra ID Vulnerability Exploited in the Wild
Severity
Critical
Detail
Microsoft has addressed a critical remote code execution vulnerability, tracked as CVE-2026-69836, affecting Microsoft Entra ID, its cloud identity service formerly known as Azure Active Directory. The vulnerability has a CVSS score of 10.0 (Critical) and was reportedly exploited in the wild.
The vulnerability is caused by deserialization of untrusted data in Microsoft Entra ID. According to Microsoft’s advisory, an unauthorized attacker could exploit the vulnerability to execute code over a network. The issue could allow an unauthenticated attacker to remotely execute code in Microsoft’s cloud identity service.
Microsoft Principal Security Engineer Robert Fitzpatrick discovered the vulnerability. Microsoft has not disclosed who was responsible for the exploitation, when the exploitation began, how many organizations were affected, or what attackers did after gaining access to the vulnerable service.
| CVE ID | Summary | CVSS Score |
| CVE-2026-69836 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | 10.0 (Critical) |
Affected Products
The vulnerability affects Microsoft Entra ID, Microsoft’s cloud identity service that verifies logins and controls access to Microsoft 365, Azure, and connected third-party applications.
Microsoft’s advisory states that the vulnerability has already been fully mitigated by Microsoft. Therefore, there is no action required from customers using the service.
Recommendation
Microsoft has fully mitigated CVE-2026-69836 within its cloud service. Customers do not need to take any action to address the vulnerability. Microsoft stated that the purpose of the CVE disclosure is to provide further transparency regarding the vulnerability and its mitigation.
Organizations should nevertheless remain vigilant because the vulnerability was exploited in the wild and affected a cloud identity service responsible for authentication and access control across Microsoft 365, Azure, and connected third-party applications.
Source
https://www.cve.org/CVERecord?id=CVE-2026-69836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
https://www.helpnetsecurity.com/2026/08/21/microsoft-entra-id-vulnerability-cve-2026-69836/
https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-entra-id-flaw-exploited-in-attacks/
