Microsoft on August 21, 2026 disclosed CVE-2026-69836, a maximum-severity flaw in Entra ID that carries a CVSS score of 10.0 and could have let an unauthenticated attacker execute code across a network. The tech giant said the vulnerability has already been fully mitigated on the service side and that no customer patch or action is required.
What Went Wrong Inside Entra ID
The bug is a classic case of CWE-502 unsafe deserialisation: Entra ID converted attacker-controlled data back into an active object without proper validation, opening a path to remote code execution, denial of service or access-control bypass. Microsoft's advisory credits principal security engineer Robert Fitzpatrick with reporting the issue. Entra ID, formerly Azure Active Directory, is the cloud identity fabric that authenticates users into Microsoft 365, Azure and thousands of connected SaaS applications, making the theoretical blast radius enormous.

Exploited Or Not? Microsoft Rewrote The Advisory
The security bulletin originally flagged the Exploited field as "Yes," a designation that prompted headlines about in-the-wild attacks. After The Hacker News contacted the company for comment, Microsoft corrected the exploitability status to "No" and clarified that CVE-2026-69836 had not been exploited before mitigation. "We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency," a Microsoft spokesperson said, echoing Redmond's evolving practice of assigning CVEs to fully mitigated cloud bugs.
Latest In A Busy Vulnerability Cycle
The Entra ID disclosure lands alongside Microsoft's blockbuster August 2026 Patch Tuesday, which addressed 421 CVEs including the Lazarus-linked AFD.sys zero-day. It also arrives days after CISA expanded the Known Exploited Vulnerabilities catalogue with Langflow, Tomcat and N-central flaws, reinforcing how quickly attackers are chaining identity and cloud bugs.
Reporting based on coverage from The Hacker News, Help Net Security and BleepingComputer.
