Microsoft has disclosed and fully mitigated a maximum-severity vulnerability in Entra ID, its cloud identity and access-management service, after publishing the security record on Thursday, August 20. The flaw, tracked as CVE-2026-69836, could allow an unauthorized attacker to execute code remotely over a network, but Microsoft says customers do not need to take action because the company repaired the hosted service itself.
The disclosure drew urgent attention on Friday because Microsoft assigned the flaw a CVSS score of 10.0, the highest level on the widely used severity scale. Entra ID, formerly called Azure Active Directory, provides authentication and access controls for organizations using Microsoft cloud applications and resources, placing the service at a critical point in many corporate security systems.
Microsoft and the US National Vulnerability Database describe the weakness as deserialization of untrusted data, catalogued as CWE-502. This type of error can occur when software reconstructs data supplied from an untrusted source without sufficient validation. The published score says an attack could be launched remotely with low complexity, without privileges and without any action from a user, with potentially high effects on confidentiality, integrity and availability.
Early reports said attackers had exploited the vulnerability because Microsoft’s bulletin initially marked its exploitation field as yes. Microsoft corrected that field on August 21 after a media inquiry and stated that the vulnerability had not been exploited in the wild. The US vulnerability record also listed exploitation as none in an update on Friday, while noting that the issue is automatable and could have a total technical impact.
Microsoft credited principal security engineer Robert Fitzpatrick with discovering and reporting the problem. Public records contain no exploit code or detailed attack chain, and the company has not released technical information that would make abuse easier. Because Entra ID is an exclusively hosted service operated by Microsoft, the provider could deploy the mitigation centrally instead of asking administrators to install a conventional software update.
The corrected status reduces the immediate incident risk, but the perfect severity score shows why cloud identity infrastructure remains a high-value security target. Administrators do not have a patch to apply, according to Microsoft, yet organizations can continue reviewing identity logs and access policies as routine security practice. Further details would depend on any additional technical guidance or transparency information Microsoft chooses to publish.
Comments