Microsoft has confirmed it has patched a critical vulnerability in its Entra ID identity and access management (IAM) platform, previously known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, has a maximum severity rating and has been exploited in active attacks.
The vulnerability involves the deserialization of untrusted data within Entra ID, which allowed an unauthorized attacker to execute code over a network. Microsoft stated that the attacks required no prior privileges and were of low complexity.
Robert Fitzpatrick, a principal security engineer at Microsoft, is credited with discovering CVE-2026-69836. The company has fully mitigated the issue and stated that users of the service do not need to take any action. Microsoft also noted that exploit code for this specific vulnerability is not yet publicly available.
Entra ID is a cloud-based IAM platform that provides authentication, policy enforcement, and protection for Microsoft 365, Azure, and Dynamics CRM Online customers across various applications and resources.
While Microsoft confirmed the exploitation of CVE-2026-69836, the company did not provide additional details regarding the nature or scope of the attacks.
This patch follows other recent critical security updates from Microsoft. The company addressed four additional maximum-severity flaws, three of which enabled unauthenticated attackers to remotely escalate privileges on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, CVE-2026-65770, allowed remote code execution on an Azure Managed Instance for Apache Cassandra.
In September 2025, Microsoft also patched a critical Entra ID privilege escalation flaw, CVE-2025-55241, which was reported by security researcher Dirk-jan Mollema of Outsider Security. That vulnerability could have allowed attackers to gain complete access to the Microsoft Entra ID tenant of any company globally.
Separately, the Cybersecurity and Infrastructure Security Agency (CISA) recently flagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.






