Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)
Reported exploitedMicrosoft Entra IDOur summary
Microsoft has addressed a critical remote code execution flaw identified as CVE-2026-69836 within its Entra ID cloud identity service, which is actively being exploited in the wild. Rated with the maximum CVSS score of 10.0, this vulnerability stems from the deserialization of untrusted data and permits unauthenticated attackers to execute code across the network without prior credentials. The issue was discovered by internal security engineer Robert Fitzpatrick and has already been fully mitigated by Microsoft, meaning no specific remediation steps are necessary for customers. Despite confirming active exploitation, the company has not yet disclosed details regarding the threat actors involved, the timeline of attacks, or the potential scope of compromised organizations.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.