Skip to main content
Emerging ThreatsMalware & Ransomware

Microsoft patches exploited Entra ID flaw amid rising attacks

Secure server room with rows of computer servers and networking equipment.

"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft said in a security advisory published on Thursday.

CVE-2026-69836: what Microsoft found

Microsoft has patched a maximum-severity vulnerability in its Entra ID identity and access management platform that the company says has been exploited in attacks. Tracked as CVE-2026-69836, the flaw was discovered by Microsoft principal security engineer Robert Fitzpatrick and, according to Microsoft, allowed threat actors with no privileges to gain code execution in low-complexity attacks.

Entra ID — formerly known as Azure Active Directory — provides authentication, policy enforcement, and protection for Microsoft 365, Azure, and Dynamics CRM Online customers. Microsoft’s advisory states that the vulnerability arises from deserialization of untrusted data and that it permits an unauthorized attacker to execute code over a network.

The immediate fix and Microsoft’s public advisory

Microsoft says the vulnerability has already been fully mitigated by the company and that “there is no action for users of this service to take.” The company also told readers that exploit code for CVE-2026-69836 is not yet available online. Microsoft framed the CVE publication as a transparency measure: “The purpose of this CVE is to provide further transparency.”

When asked for further details on the attacks exploiting CVE-2026-69836, Microsoft did not provide additional information and a company spokesperson was not immediately available for comment when BleepingComputer sought clarification.

Other maximum-severity patches rolled out this week

Alongside CVE-2026-69836, Microsoft addressed four other maximum-severity flaws in a recent round of patches. Three of those could allow unauthenticated attackers to escalate privileges remotely: CVE-2026-65816 and CVE-2026-69555 affecting Azure Arc, and CVE-2026-65801 affecting Exchange Online. The fourth, CVE-2026-65770, enabled remote code execution on an Azure Managed Instance for Apache Cassandra.

Microsoft’s simultaneous handling of several high-severity flaws underscores the reach of its cloud services and the variety of components — from identity platforms to managed database instances and hybrid management tools — that received fixes in the same window.

Context from prior Entra ID incidents and active exploit notices

This incident follows a prior critical Entra ID issue patched in September 2025. That earlier flaw, CVE-2025-55241, was reported by Outsider Security security researcher Dirk-jan Mollema and, Microsoft said at the time, enabled attackers to gain complete access to the Microsoft Entra ID tenant of every company in the world.

Separately, on Friday the Cybersecurity and Infrastructure Security Agency (CISA) tagged a critical-severity remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited. Microsoft’s recent disclosures sit alongside such government notices in a period marked by high-severity fixes and agency-level exploit advisories.

The Blue Report 2026 — cited in the same bulletin — highlights how surface-level prevention metrics can mask post-compromise risk: “Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.” The report measures defenses technique by technique across 338 million simulations run in customer production environments.

What this means for technologists, affected enterprises, and regulators

  • Technologists and security teams: Microsoft has stated the Entra ID flaw is fully mitigated and that no action is required by users. Teams responsible for identity and access should confirm that their Entra ID service reflects Microsoft’s mitigation and remain alert for any publication of exploit code, which Microsoft says is not yet available online.
  • Affected enterprises and procurement leaders: Organizations that rely on Entra ID for Microsoft 365, Azure, or Dynamics CRM Online should take the advisory at face value but also note the company’s recent history of severe Entra ID issues, including the September 2025 flaw that Microsoft said could enable tenant-wide access. These past incidents form part of the operational risk environment for cloud identity services.
  • Regulators and incident-response authorities: CISA’s active-exploit tagging of a separate Windows IKE component underscores that government notices continue to appear alongside vendor advisories. Agencies monitoring cloud and identity risk will likely factor Microsoft’s multiple recent maximum-severity patches into their ongoing assessments.

Microsoft’s public framing is direct: the Entra ID vulnerability that allowed unauthenticated code execution has been mitigated and users need not take action. Yet the company supplied only limited technical detail, declined to provide additional comment to BleepingComputer at the time of inquiry, and acknowledged that exploit code is not currently public. Given the recent series of maximum-severity fixes and prior Entra ID incidents, the immediate risk appears contained; the central question left on the record is whether exploit code — and any related operational indicators — will surface after the vendor’s mitigation.

Read the original BleepingComputer report