Microsoft Says CVSS 10.0 Entra ID Code Execution Flaw Was Exploited Before Server-Side Fix
ID: 1cfc6e87-5bf1-52bd-8323-fc38c09af007
STIX ID: report--1cfc6e87-5bf1-52bd-8323-fc38c09af007
Feed Name: The Cyber Express
Threat Score
Microsoft disclosed CVE-2026-69836, a CVSS 10.0 unauthenticated remote code execution vulnerability in Entra ID (formerly Azure AD) that was exploited in the wild and mitigated server-side; the flaw is due to deserialization of untrusted data, no public exploit or IOCs have been released, and organizations are advised to audit Entra ID sign-in and token issuance logs for anomalous service principal activity and privilege changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
