← Terug naar overzicht

CVE-2026-69836 describes a critical deserialization of untrusted data vulnerability in Microsoft Entra ID. The flaw allows an unauthorized attacker to execute arbitrary code over a network without requiring authentication. Deserialization vulnerabilities are considered high severity as they can lead to full system compromise. The vulnerability was published via NVD and has an accompanying Microsoft Security Response Center advisory. Microsoft Entra ID is a widely used cloud-based identity and access management service, making this vulnerability particularly impactful across enterprise environments. Organizations relying on Entra ID for authentication and authorization should treat this with urgency and apply available patches promptly.

Affected products

  • Microsoft Entra ID

Related CVE's

  • CVE-2026-69836

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities