{
  "id": 2397940,
  "title": "Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack",
  "url": "https://urgent.news/2026/08/21/microsoft-sounds-alarm-as-perfect-10-entra-id-flaw-comes-under-attack-2397940",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T10:15:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/cyber-crime/2026/08/21/microsoft-sounds-alarm-as-perfect-10-entra-id-flaw-comes-under-attack/5290925"
  },
  "original_language": "en",
  "account": "Microsoft has issued an urgent warning following the discovery of a critical vulnerability in Entra ID, a cloud identity service used by millions of customers. Known as CVE-2026-69836, the flaw carries the maximum CVSS score of 10.0, indicating it could be exploited remotely by an attacker without any user interaction or authentication. Microsoft confirmed that the vulnerability had already been actively exploited in the wild as of Thursday. Entra ID, formerly Azure Active Directory, plays a central role in identity and access management for Microsoft customers, handling authentication and access to cloud applications and other corporate resources.\n\nThe root cause of the vulnerability is unsafe deserialization, a security issue where software reconstructs data from an untrusted source without proper validation. This flaw allows an unauthorized attacker to execute code over a network, making it significantly more dangerous than many other security issues. Microsoft's advisory does not provide details about who is exploiting the flaw, when the attacks began, or how widespread they are. The company has not disclosed any technical information about the attack chain or what actions the attackers have taken once they have successfully exploited the vulnerability.\n\nFortunately, there is no need for customers to apply any patches or take any other actions, as Microsoft has already fully mitigated the vulnerability on its side. The company stated that there is no action required for users of the service. The vulnerability's perfect 10 rating is attributed to its remote exploitable nature, low attack complexity, lack of privileges needed, and potential for significant impact on confidentiality, integrity, and availability. Microsoft recognized the vulnerability's existence through the diligent work of principal security engineer Robert Fitzpatrick, although the specifics of how the company discovered the exploitation in the wild are not provided.",
  "summary": "Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack",
        "url": "https://urgent.news/2026/08/21/microsoft-sounds-alarm-as-perfect-10-entra-id-flaw-comes-under-attack",
        "published": "2026-08-21T10:15:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}