← Back to overview

A critical deserialization of untrusted data vulnerability has been identified in Microsoft Entra ID, formerly known as Azure Active Directory. The vulnerability allows an unauthorized attacker to execute arbitrary code over a network without authentication. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. The flaw is tracked as CVE-2026-69836 and is documented in both the Microsoft Security Response Center and the NVD. Organizations using Microsoft Entra ID are urged to apply available security patches immediately. Forensic triage requirements have also been outlined by CISA as part of the BOD 26-04 implementation guidance. The vulnerability poses a significant risk to identity and access management infrastructure relying on Microsoft cloud services.

Affected products

  • Azure Active Directory
  • Microsoft Entra ID

Related CVE's

  • CVE-2026-69836

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities