LIVE · cybersecurity feed
Live wire
vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

zeroday.news ·

Microsoft has confirmed it has patched a critical vulnerability in its Entra ID identity and access management (IAM) platform, previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity rating and has been exploited in active attacks.

The vulnerability involves the deserialization of untrusted data within Entra ID, which allowed an unauthorized attacker to execute code over a network. Microsoft stated that the attacks required no prior privileges and were of low complexity.

Robert Fitzpatrick, a principal security engineer at Microsoft, is credited with discovering CVE-2026-69836. The company has fully mitigated the issue and stated that users of the service do not need to take any action. Microsoft also noted that exploit code for this specific vulnerability is not yet publicly available.

Entra ID is a cloud-based IAM platform that provides authentication, policy enforcement, and protection for Microsoft 365, Azure, and Dynamics CRM Online customers across various applications and resources.

While Microsoft confirmed the exploitation of CVE-2026-69836, the company did not provide additional details regarding the nature or scope of the attacks.

This patch follows other recent critical security updates from Microsoft. The company addressed four additional maximum-severity flaws, three of which enabled unauthenticated attackers to remotely escalate privileges on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, CVE-2026-65770, allowed remote code execution on an Azure Managed Instance for Apache Cassandra.

In September 2025, Microsoft also patched a critical Entra ID privilege escalation flaw, CVE-2025-55241, which was reported by security researcher Dirk-jan Mollema of Outsider Security. That vulnerability could have allowed attackers to gain complete access to the Microsoft Entra ID tenant of any company globally.

Separately, the Cybersecurity and Infrastructure Security Agency (CISA) recently flagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

SickKids data breach exposes employee and job applicant info

Toronto's Hospital for Sick Children (SickKids) says a cybersecurity incident exposed the personal information of some current and former employees and job applicants, stemming from a flaw in third-party software. Clinical systems and patient records were not affected. (264) [...]

CVE-2026-19478critical

GitLab Critical GraphQL Flaw Actively Exploited

GitLab has released an emergency patch for a critical vulnerability in its GraphQL API that allows unauthenticated attackers to modify or delete public projects and user data. Researchers from WatchTowr discovered the flaw, tracked as CVE-2026-19478, which has a CVSS score of 9.4 and is reportedly under active exploitation. The vulnerability affects self-managed installations, and users are urged to upgrade to specific patched versions, as older branches will not receive direct fixes.

CVE-2026-73570critical

Poland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite Flaw

CERT Polska confirmed active exploitation of CVE-2026-73570, a critical unauthenticated RCE in Zimbra Collaboration Suite patched on July 20. CERT Polska, Poland’s national computer emergency response team, confirmed this week that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite tracked as CVE-2026-73570. The flaw allows unauthenticated remote code exec

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

malware

Hackers abuse FTP server banners to deliver new Windows malware

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]

ai

More Incidents of AIs Going Rogue in Cybersecurity Challenges

The AI Security Institute has a new report of AI systems engaging in “unsanctioned behavior”—what I have been calling “genie behavior—while being tested on their cybersecurity capabilities. The incident stemmed from a single evaluation where agents were given a task of solving a cyber security challenge. We ran this challenge 122 times across several models. Our investigation found that in 10 of t