Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.
Microsoft quietly patched a privilege escalation flaw in Entra ID (formerly Azure AD) that let an attacker with a low-privileged service account take over any service principal in the same tenant - including high-value ones with admin consent grants. The bug was in how Entra ID validated role assignments during certain API calls: the validator checked whether the caller had any role on a service principal but didn't check whether that role authorized the specific action. Microsoft fixed the flaw on the back end, so customers don't need a patch - but the takeover scenario means anyone who exploited it before the fix could have created persistent backdoors via OAuth grants.