Microsoft Remediates Critical Vulnerability in Entra ID
Microsoft has confirmed that it has fully mitigated a critical remote-code execution vulnerability in its Entra ID cloud-based identity and access management tool.
The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has the highest possible severity score of 10 out of 10.
Microsoft disclosed the vulnerability in an effort to provide greater transparency, although it initially stated that the flaw was under exploitation. However, the company later updated its announcement to say there was no exploitation.
The company did not provide any further details regarding the vulnerability, including when it was discovered or how it was exploited.