← Back to overview

Microsoft disclosed a maximum-severity vulnerability in Microsoft Entra ID (formerly Azure Active Directory), tracked as CVE-2026-69836 with a CVSS score of 10.0. The flaw allows remote code execution on the cloud-based identity and access management service. Microsoft confirmed the vulnerability has been actively exploited in the wild. Despite active exploitation, Microsoft stated that no customer action is required to remediate the issue. The vulnerability affects a widely used enterprise identity platform, making it a critical risk for organizations relying on Microsoft's cloud identity services.

Technical details

CVE-2026-69836 is a maximum-severity (CVSS 10.0) remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory), Microsoft's cloud-based identity and access management service. The vulnerability is caused by deserialization of untrusted data, classified under CWE-502. The flaw allows an unauthorized, unauthenticated attacker to execute arbitrary code over a network by sending specially crafted serialized data that the service deserializes without proper validation. This class of vulnerability can also lead to denial-of-service or access control bypass. The vulnerability was discovered and reported by Principal Security Engineer Robert Fitzaptrick. The flaw has been confirmed as exploited in the wild, though no technical details about the exploitation method, timeline, or threat actors behind the exploitation of this specific CVE have been disclosed.

Mitigation steps

No customer action is required. Microsoft has fully mitigated the vulnerability server-side on its cloud infrastructure. Users and administrators of Microsoft Entra ID do not need to apply any patches or take any remediation steps. Organizations should monitor Microsoft Security Response Center (MSRC) advisories for any future updates regarding this vulnerability.

Affected products

  • Microsoft Entra ID (formerly Azure Active Directory / Azure AD)

Related CVE's

  • CVE-2026-68820
  • CVE-2026-69836

Related threat actors

  • Lazarus Group

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities