Microsoft's Entra ID Identity Platform Hit with Maximum-Severity Vulnerability
Microsoft has confirmed that its Entra ID identity and access platform was vulnerable to maximum-severity attacks before a fix was implemented. The vulnerability, tracked as CVE-2026-69836, carries a CVSS severity score of 10.0 and could allow an unauthorized attacker to execute code remotely over a network.
The issue was caused by the deserialization of untrusted data in Entra ID, which is used for authentication, access control, administrative privilege, and application connectivity across Microsoft's cloud ecosystem.
Microsoft has stated that the vulnerability has been fully mitigated within its infrastructure, but customers are still left to assess whether any activity before the fix created lasting exposure within their environments.