Microsoft Fixes Critical Vulnerability in Entra ID Cloud Identity Service
Microsoft has patched a critical remote code execution vulnerability in its Entra ID cloud identity service. The flaw, tracked as CVE-2026-69836, received a CVSS score of 10.0, the highest possible rating.
The vulnerability affects Microsoft's Entra ID platform, formerly known as Azure Active Directory. It can be exploited over a network with low attack complexity and requires no privileges or user interaction.
Microsoft said it identified and fixed the vulnerability before publishing the CVE. The company confirmed that it was not exploited in the wild and called the revision an 'informational change only.'