Microsoft Fixes High-Severity Entra ID Flaw Tracked as CVE-2026-69836
A major vulnerability in Microsoft's Entra ID identity platform has been patched by the company after earning a maximum severity score of 10.0 on the CVSS scale.
The flaw, tracked as CVE-2026-69836, was discovered internally by Robert Fitzpatrick, a principal security engineer at Microsoft, and could have allowed an attacker to seize control of affected systems over the internet with no login credentials or user interaction required.
Making matters worse, the vulnerability was classified as having low complexity, which means it required minimal technical difficulty to exploit. Fortunately for customers, Microsoft had already deployed a fix before publicly disclosing the issue, and users do not need to take any action to protect themselves.