Microsoft has confirmed a critical remote code execution vulnerability in Entra ID, its cloud identity platform used across Microsoft 365, Azure, and thousands of third-party apps. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 — the maximum possible — and stems from a deserialization bug that let attackers run arbitrary code remotely, with no login required.
Microsoft disclosed it on August 20, 2026, with the advisory's exploitation flag set to "Yes." A day later the company flipped that flag to "No," and has not explained why. No exploitation has ever been confirmed, and the flaw was found by one of Microsoft's own security engineers.
Because Entra ID is a managed cloud service, Microsoft patched it server-side; the company says the issue is fully mitigated and there is no action for customers to take. What it hasn't said is how long the service was vulnerable, whether any tenant data was reached, or why the exploitation flag changed.
With exploitation unconfirmed, there's no incident to respond to — but the audit is easy to do. Review Entra ID sign-in logs, conditional access policies, and privileged role assignments for anything anomalous predating the fix.
Source: Cybersecurity News