Microsoft Patches Critical Entra ID RCE Flaw (CVSS 10.0)
Microsoft has patched a maximum-severity vulnerability in its Entra ID cloud identity service that could allow remote code execution over a network. Tracked as CVE-2026-69836 with a CVSS score of 10.0, the flaw stems from deserialization of untrusted data—a class of bug that occurs when an application converts attacker-controlled input back into active objects or code structures without proper validation. Such weaknesses can enable code execution, denial-of-service attacks, or access control bypasses, potentially letting an adversary perform unauthorized actions within a target environment. Entra ID, formerly known as Azure Active Directory, serves as the identity backbone for countless enterprise Microsoft 365 deployments.
The disclosure drew attention after Microsoft's security bulletin initially listed the vulnerability as "Exploited: Yes." However, following inquiries from The Hacker News, the company corrected the status to "No" and confirmed that CVE-2026-69836 "was not exploited in the wild." A Microsoft spokesperson stated the flaw was "identified and addressed with a fix" released "for greater transparency" and that no additional customer actions were required. Microsoft credited principal security engineer Robert Fitzpatrick for discovering and reporting the issue.
Because Microsoft has fully mitigated the flaw on its side, Entra ID users do not need to apply patches or change configurations. Organizations relying on Entra ID for authentication and identity management are nonetheless advised to harden their overall posture—running an SSL/TLS checker against identity endpoints and using a password checker to confirm no compromised credentials are active in the directory. A broader privacy checkup can also help surface weak identity hygiene.
Separately, Microsoft earlier this month addressed CVE-2026-68820 (CVSS 7.0), a high-severity privilege escalation bug in the Windows Ancillary Function Driver for WinSock that was actively exploited as a zero-day by the North Korea-linked Lazarus Group as part of a long-running campaign dubbed Operation Dream Job. Security teams should keep identity provider logs under active monitoring and ensure timely patching across Windows endpoints.