Critical Entra ID Bug Exposes Millions of Enterprise Tenants to Remote Code Execution Attacks
A critical vulnerability has been discovered in Microsoft's cloud-based identity and access management platform, Entra ID. The bug, tracked as CVE-2026-69836, is a remote code execution flaw that allows attackers to execute arbitrary code on the network without needing any authentication or user interaction.
The vulnerability was disclosed on August 20, 2026, and carries the maximum severity rating of Critical. It stems from a deserialization of untrusted data issue, which can be exploited by sending malicious serialized data to a vulnerable endpoint.
An attacker who gains code execution on the identity layer could potentially pivot into connected cloud workloads, hijack authentication tokens, or manipulate access policies across an entire organization's Microsoft ecosystem. Microsoft has already rolled out the fix on its own infrastructure, and there are no update packages or configuration changes for customers to apply.
Microsoft credited security researcher Robert Fitzpatrick for reporting the issue through coordinated disclosure. The company has taken a proactive approach to transparency, giving security teams visibility into threats that touched their environment even though the fix was applied server-side before most organizations knew of the flaw.