AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 21 Aug, 15:38

A maximum-severity flaw in Microsoft Entra ID was exploited before Microsoft patched it

Microsoft $MSFT disclosed CVE-2026-69836, a 10/10-severity remote code execution flaw in Entra ID that attackers exploited before a fix shipped. Per BleepingComputer and The Hacker News.

Microsoft $MSFT disclosed on Thursday, August 20, 2026, that a maximum-severity flaw in Entra ID, tracked as CVE-2026-69836 with a CVSS score of 10.0, had been exploited in the wild. Entra ID, formerly Azure Active Directory, is the cloud identity platform behind sign-ins for Microsoft 365, Azure, and Dynamics CRM Online. The flaw, a deserialization-of-untrusted-data bug discovered by Microsoft principal security engineer Robert Fitzpatrick, let unprivileged attackers execute code over the network in low-complexity attacks, according to Microsoft. The company says the vulnerability is already fully mitigated on its own infrastructure, so no customer action is required, and that exploit code is not yet public. It is the second maximum-severity Entra ID flaw disclosed in under a year, after a September 2025 bug that exposed every company's tenant to complete access. Sources: BleepingComputer, The Hacker News.

#cyber
Published on