Microsoft Fixes Critical Entra ID Flaw Exploited by Attackers
Microsoft has patched a maximum-severity vulnerability in its Entra ID identity and access management (IAM) platform that was exploited in attacks. The flaw, tracked as CVE-2026-69836, allowed threat actors with no privileges to gain code execution in low-complexity attacks.
Formerly known as Azure Active Directory (Azure AD), Entra ID provides authentication, policy enforcement, and protection across apps and resources for Microsoft 365, Azure, or Dynamics CRM Online customers. Microsoft principal security engineer Robert Fitzpatrick discovered the critical security flaw.
The company says exploit code for CVE-2026-69836 is not yet available online, and users don't need to take any action since the flaw has already been fully patched. 'Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,' Microsoft said in a security advisory.
Microsoft didn't share additional information about attacks exploiting the CVE-2026-69836 flaw, and a spokesperson was not immediately available for comment when asked for more details. This is one of several maximum-severity flaws patched by the company recently.