logo

Microsoft Says CVSS 10.0 Entra ID Code Execution Flaw Was Exploited Before Server-Side Fix

ID: 1cfc6e87-5bf1-52bd-8323-fc38c09af007

STIX ID: report--1cfc6e87-5bf1-52bd-8323-fc38c09af007

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Mihir Bagwe

...
...

Microsoft disclosed CVE-2026-69836, a CVSS 10.0 unauthenticated remote code execution vulnerability in Entra ID (formerly Azure AD) that was exploited in the wild and mitigated server-side; the flaw is due to deserialization of untrusted data, no public exploit or IOCs have been released, and organizations are advised to audit Entra ID sign-in and token issuance logs for anomalous service principal activity and privilege changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.