Microsoft confirmed the issue was fully mitigated and reported no confirmed exploitation in the wild.
Key Takeaways:
Microsoft has patched a critical vulnerability in Microsoft Entra ID (formerly known as Azure Active Directory) that carries the maximum CVSS score of 10.0. The flaw could have allowed unauthenticated attackers to remotely execute malicious code over the network.
Microsoft first disclosed this Entra ID vulnerability (CVE-2026-69836), reported by security engineer Robert Fitzpatrick on August 20. It could allow remote code execution without requiring user interaction or prior authentication. This flaw stemmed from the improper handling of serialized data, which created a scenario in which an attacker could potentially execute malicious code across the network.
Microsoft patched this issue directly within its infrastructure before customers needed to take action. Early reports suggested that this flaw had been exploited in the wild, but Microsoft later updated its guidance to clarify that no confirmed exploitation had occurred.
“Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft explained in its advisory. “This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.”
The flaw attracted significant attention because Entra ID serves as the authentication backbone for Microsoft cloud services and many enterprise applications. A successful compromise of such a central identity service could potentially affect authentication, authorization, and access management across large numbers of organizations.
Microsoft has released 22 security patches covering multiple cloud services and products. In addition to the Entra ID vulnerability, Microsoft addressed several other critical Azure, Exchange Online, Fabric, and Partner Center flaws, including multiple vulnerabilities that also received very high severity ratings.