Microsoft mitigates exploited CVSS 10.0 Entra ID code-execution flaw

Microsoft has disclosed and fully mitigated CVE-2026-69836, a maximum-severity remote code execution vulnerability in Microsoft Entra ID that the company says has been exploited in the wild. The flaw carries a CVSS score of 10.0 and affects Microsoft’s cloud-based identity and access management service, formerly called Azure Active Directory or Azure AD.
Microsoft said no customer action is required because the service-side mitigation has already been completed. The company did not disclose how the vulnerability was exploited, when exploitation began, whether it remains active, or how the activity was detected.
Untrusted-data deserialization enabled network code execution
Microsoft describes CVE-2026-69836 as deserialization of untrusted data in Entra ID. An unauthorised attacker could exploit the issue over a network to execute code, the company said.
Deserialization flaws arise when an application converts attacker-controlled data into an active object or code structure without sufficient validation. Depending on the affected implementation, such weaknesses can lead to code execution, denial of service, or access-control bypasses that enable unauthorised activity.
Microsoft credited Principal Security Engineer Robert Fitzaptrick with discovering and reporting the issue. Beyond the advisory, the company has not published technical indicators, an attack chain, or details of the in-the-wild exploitation.
Identity services remain a critical security dependency
Entra ID is used for cloud identity and access management, making the vulnerability notable even though remediation was handled by Microsoft. Organisations using the service do not need to deploy a patch, but they should retain the advisory in their security records and consider it when reviewing identity-related monitoring and incident-response processes.
The disclosure follows other Microsoft security fixes, including the Windows vulnerabilities catalogued in Microsoft Windows vulnerability findings as a reminder that identity platforms and endpoint components can both form part of an organisation’s exposure management work.
For security teams, the practical implication is to document Microsoft’s completed mitigation, confirm that cloud-service security notifications reach the right responders, and use established identity incident procedures if suspicious activity is identified.

