Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

Microsoft has confirmed it has patched a critical vulnerability in its Entra ID identity and access management (IAM) platform, previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity rating and has been exploited in active attacks.
The vulnerability involves the deserialization of untrusted data within Entra ID, which allowed an unauthorized attacker to execute code over a network. Microsoft stated that the attacks required no prior privileges and were of low complexity.
Robert Fitzpatrick, a principal security engineer at Microsoft, is credited with discovering CVE-2026-69836. The company has fully mitigated the issue and stated that users of the service do not need to take any action. Microsoft also noted that exploit code for this specific vulnerability is not yet publicly available.
Entra ID is a cloud-based IAM platform that provides authentication, policy enforcement, and protection for Microsoft 365, Azure, and Dynamics CRM Online customers across various applications and resources.
While Microsoft confirmed the exploitation of CVE-2026-69836, the company did not provide additional details regarding the nature or scope of the attacks.
This patch follows other recent critical security updates from Microsoft. The company addressed four additional maximum-severity flaws, three of which enabled unauthenticated attackers to remotely escalate privileges on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, CVE-2026-65770, allowed remote code execution on an Azure Managed Instance for Apache Cassandra.
In September 2025, Microsoft also patched a critical Entra ID privilege escalation flaw, CVE-2025-55241, which was reported by security researcher Dirk-jan Mollema of Outsider Security. That vulnerability could have allowed attackers to gain complete access to the Microsoft Entra ID tenant of any company globally.
Separately, the Cybersecurity and Infrastructure Security Agency (CISA) recently flagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs