Microsoft Discloses Critical Vulnerability in Entra ID Cloud Service
Microsoft disclosed a critical vulnerability in its Entra ID cloud identity management service on August 20, 2026. The Common Vulnerability Scoring System (CVSS) v3.1 score for CVE-2026-69836 is the maximum possible value of 10.0.
The company stated that mitigations have already been applied to the service side and no user action is required. However, Microsoft disclosed the information in accordance with its vulnerability disclosure policy for service-side issues, which aims to ensure transparency regarding the security posture of cloud services.
The vulnerability poses a risk that an unauthenticated attacker could execute code over the network due to a flaw in the handling of deserialization of untrusted data. Despite this, Microsoft has not observed any exploitation and assesses the likelihood as low.