Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack

Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely

Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack

Microsoft has issued an urgent warning following the discovery of a critical vulnerability in Entra ID, a cloud identity service used by millions of customers. Known as CVE-2026-69836, the flaw carries the maximum CVSS score of 10.0, indicating it could be exploited remotely by an attacker without any user interaction or authentication.

Microsoft confirmed that the vulnerability had already been actively exploited in the wild as of Thursday. Entra ID, formerly Azure Active Directory, plays a central role in identity and access management for Microsoft customers, handling authentication and access to cloud applications and other corporate resources.

The root cause of the vulnerability is unsafe deserialization, a security issue where software reconstructs data from an untrusted source without proper validation. This flaw allows an unauthorized attacker to execute code over a network, making it significantly more dangerous than many other security issues. Microsoft's advisory does not provide details about who is exploiting the flaw, when the attacks began, or how widespread they are.

The company has not disclosed any technical information about the attack chain or what actions the attackers have taken once they have successfully exploited the vulnerability.

Fortunately, there is no need for customers to apply any patches or take any other actions, as Microsoft has already fully mitigated the vulnerability on its side. The company stated that there is no action required for users of the service. The vulnerability's perfect 10 rating is attributed to its remote exploitable nature, low attack complexity, lack of privileges needed, and potential for significant impact on confidentiality, integrity, and availability.

Microsoft recognized the vulnerability's existence through the diligent work of principal security engineer Robert Fitzpatrick, although the specifics of how the company discovered the exploitation in the wild are not provided.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Friday 21 August →