Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was di

Microsoft has issued a patch for a critical remote code execution vulnerability, identified as CVE-2026-69836, within its Entra ID cloud identity service. The company confirmed that the vulnerability has been actively exploited in the wild. Entra ID, previously known as Azure Active Directory, is a core Microsoft service responsible for authenticating user logins and managing access to Microsoft 365, Azure, and integrated third-party applications.
The vulnerability carries the maximum CVSS score of 10.0, indicating its severe potential impact. It was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick. According to Microsoft's advisory, the flaw stems from the deserialization of untrusted data within Entra ID, which could enable an unauthenticated attacker to execute arbitrary code remotely over a network.
Despite the in-the-wild exploitation, Microsoft stated that no customer action is required. The company asserted that it has already fully mitigated the vulnerability on its end. The purpose of releasing the CVE, according to Microsoft, is to provide transparency to its users regarding the issue.
Microsoft has not publicly disclosed details regarding the identity of the attackers, the timeline of the exploitation, the number of organizations potentially impacted, or the specific actions taken by the attackers once they compromised the vulnerable service.

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [





The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop.

Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.