LIVE · cybersecurity feed
Live wire
CVE-2026-69836critical

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity service, formerly Azure Active Directory, that verifies logins and controls access to Microsoft 365, Azure, and connected third-party apps. Tracked as CVE-2026-69836, with the maximum CVSS score of 10.0, the vulnerability was di

zeroday.news ·

Microsoft has issued a patch for a critical remote code execution vulnerability, identified as CVE-2026-69836, within its Entra ID cloud identity service. The company confirmed that the vulnerability has been actively exploited in the wild. Entra ID, previously known as Azure Active Directory, is a core Microsoft service responsible for authenticating user logins and managing access to Microsoft 365, Azure, and integrated third-party applications.

The vulnerability carries the maximum CVSS score of 10.0, indicating its severe potential impact. It was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick. According to Microsoft's advisory, the flaw stems from the deserialization of untrusted data within Entra ID, which could enable an unauthenticated attacker to execute arbitrary code remotely over a network.

Despite the in-the-wild exploitation, Microsoft stated that no customer action is required. The company asserted that it has already fully mitigated the vulnerability on its end. The purpose of releasing the CVE, according to Microsoft, is to provide transparency to its users regarding the issue.

Microsoft has not publicly disclosed details regarding the identity of the attackers, the timeline of the exploitation, the number of organizations potentially impacted, or the specific actions taken by the attackers once they compromised the vulnerable service.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Friday Squid Blogging: Neon Flying Squid

The neon flying squid can fly in formation. The shoal of about 100 squid rose unexpectedly from a patch of the Pacific Ocean around 370 miles from Tokyo and glided near the boat for about 30 metres. The astonished researchers were the first to capture photographs of such a thing, which looked like the early stages of an alien invasion. They were probably neon flying squid (Ommastrephes bartramii),

security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

security

Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.