logo

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

ID: 1edca2f6-33d8-5db9-8924-e68e51eadd0b

STIX ID: report--1edca2f6-33d8-5db9-8924-e68e51eadd0b

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed a maximum-severity remote code execution vulnerability in Entra ID (CVE-2026-69836, CVSS 10.0) that it says has been exploited in the wild; the company states the issue has been fully mitigated and no customer action is required. The report also notes a separate recent Windows privilege-escalation zero-day (CVE-2026-68820) that was exploited by the North Korea-linked Lazarus Group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.