← All articles

Exploited Entra ID flaw scored a perfect ten but was fixed in Microsoft's cloud

Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.

Check
No patching is required since Microsoft fixed this in its cloud, but review Entra ID sign-in and audit logs for suspicious service-principal changes, role assignments, and unusual token or admin activity.
Affected
Organizations relying on Microsoft Entra ID for identity (CVE-2026-69836); the flaw allowed unauthenticated remote code execution in the identity service itself, though Microsoft states it is now fully mitigated.
Fix
Treat this as a prompt to hunt for identity compromise, not to patch: review privileged accounts, tokens, and app registrations for anomalies, tighten conditional access, and monitor Entra logs.