Microsoft Patches Critical Entra ID Vulnerability with Maximum CVSS Score
A critical Entra ID vulnerability has been patched by Microsoft, which had the potential to allow unauthenticated attackers to remotely execute malicious code over a network. The flaw, identified as CVE-2026-69836, carried a CVSS score of 10.0 and stemmed from improper deserialization of serialized data.
Microsoft first disclosed this Entra ID vulnerability on August 20, reported by security engineer Robert Fitzpatrick. It allowed remote code execution without requiring user interaction or prior authentication.
The issue was fully mitigated by Microsoft within its infrastructure before customers needed to take action. Early reports suggested that the flaw had been exploited in the wild, but Microsoft later updated its guidance to clarify that no confirmed exploitation had occurred.