Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack
Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely
Microsoft has addressed a critical vulnerability in its Entra ID, previously exploited by attackers, which could allow unauthorized individuals to execute code remotely within the cloud identity service. The flaw, identified as CVE-2026-69836, carries the highest possible CVSS score of 10.0. Microsoft disclosed the issue on Thursday, acknowledging that exploitation had already been observed in the wild.
Entra ID, formerly known as Azure Active Directory, plays a central role in identity and access management for Microsoft customers, handling authentication and access to cloud applications and other corporate resources. The vulnerability arises from insecure deserialization, a process where software reconstructs data from an untrusted source without proper validation.
An attacker could exploit this weakness remotely over a network, requiring no account or user action. Microsoft has not disclosed the identity of the attackers, the start date, the extent of the attacks, or the actions taken by the threat actors post-exploitation. No customer-deployed patch is necessary as Microsoft has fully mitigated the vulnerability on its side.
The company credited security engineer Robert Fitzpatrick for discovering and reporting the issue. Despite Microsoft closing the vulnerability, customers may still be interested in understanding the extent of the exploitation before it was stopped.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.