Microsoft has issued a patch for a critical remote code execution vulnerability, identified as CVE-2026-69836, within its Entra ID cloud identity service. The company confirmed that the vulnerability has been actively exploited in the wild. Entra ID, previously known as Azure Active Directory, is a core Microsoft service responsible for authenticating user logins and managing access to Microsoft 365, Azure, and integrated third-party applications.
The vulnerability carries the maximum CVSS score of 10.0, indicating its severe potential impact. It was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick. According to Microsoft's advisory, the flaw stems from the deserialization of untrusted data within Entra ID, which could enable an unauthenticated attacker to execute arbitrary code remotely over a network.
Despite the in-the-wild exploitation, Microsoft stated that no customer action is required. The company asserted that it has already fully mitigated the vulnerability on its end. The purpose of releasing the CVE, according to Microsoft, is to provide transparency to its users regarding the issue.
Microsoft has not publicly disclosed details regarding the identity of the attackers, the timeline of the exploitation, the number of organizations potentially impacted, or the specific actions taken by the attackers once they compromised the vulnerable service.






