CVE-2026-69836

Published Aug 20, 2026

Last updated 2 days ago

CVSS critical 10.0
Microsoft Entra ID

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-69836 is a remote code execution (RCE) vulnerability identified in Microsoft Entra ID, formerly known as Azure Active Directory. This flaw stems from the deserialization of untrusted data, which enables an unauthorized attacker to execute code over a network. The vulnerability allows an attacker to inject malicious object data that is executed during processing, potentially compromising user accounts, data, or the entire identity platform. Microsoft has fully mitigated this vulnerability on its infrastructure, meaning no customer action is required. While some initial reports suggested the vulnerability had been exploited in the wild, Microsoft later clarified that it was not. The company disclosed the vulnerability for transparency, crediting Principal Security Engineer Robert Fitzpatrick for its discovery.

Description
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Undergoing Analysis
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

36

  1. CVSS 10.0 στο Microsoft Entra ID: η Microsoft διόρθωσε την CVE-2026-69836, που κατά την εταιρεία θα μπορούσε να επιτρέψει απομακρυσμένη εκτέλεση κώδικα χωρίς δικαιώματα ή ενέργε

    @hacksgreece

    23 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-69836 | Entra ID | CVSS 10.0 RCE por deserialización. Sin login. Sin clic. En el servicio que autentica Microsoft 365 y Azure. Microsoft ya lo mitigó en su infraestructura. No hay parche que apliques tú. Lo grave no es “¿ya lo parcheé?”. Es que el plano de

    @BotBauR

    23 Aug 2026

    585 Impressions

    1 Retweet

    6 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 #Microsoft Entra ID Faces Maximum-Severity Security Emergency as #CVE-2026-69836 Reportedly Comes Under Active Exploitation + Video -Fact Checker: ✅: 2 ❌: 1 || 2/3 → Score: 66% ⚖️ -Prediction: 📈 1 Positive | 📉 0 Negative https://t.co/5aYMUEA4Zt

    @undercode_news

    23 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Los "swarming attacks" de C2C en Wallapop o eBay tienen una cosa muy sucia: no necesitan romper nada, sólo coordinar muchas manos y mucho timing. Y mientras Chema lo baja a tierra, Microsoft acaba de mover una ficha fuerte en Entra ID: CVE-2026-69836, CVSS 10.0, explotada en la

    @FedeJoelH

    23 Aug 2026

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Microsoft Entra ID CVSS 10.0 Vulnerability Reported as Actively Exploited A maximum-severity vulnerability affecting Microsoft Entra ID has been disclosed, with Microsoft reportedly indicating that the vulnerability is being actively exploited. Tracked as CVE-2026-69836, t

    @DailyDarkWeb

    23 Aug 2026

    52921 Impressions

    107 Retweets

    476 Likes

    260 Bookmarks

    8 Replies

    5 Quotes

  6. Microsoft Entra ID CVE-2026-69836. Deserialización insegura, CVSS 10.0, explotada en la wild. Lo que hace distinto a este caso es que Microsoft dijo que la mitigación quedó del lado del servidor y que no hay que hacer nada desde el cliente. Eso, en seguridad, es oro. Porque t

    @FedeJoelH

    23 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Microsoft Entra ID -haavoittuvuus CVE-2026-69836 korostaa pilvi-identiteetin valvontaa https://t.co/CnezdZCqSa https://t.co/PLZgS2lBmH

    @n1xupartanen

    23 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Microsoft fixt Entra-ID-Lücke (CVE-2026-69836) mit CVSS 10,0 und RCE-Risiko: https://t.co/Wwc7HrowV4 - #hacker #news #technology #technologie #it #informationstechnologie #hacking #computer #nerds #itsicherheit #itsecurity #itnews #cybercrime #cybersecurity #hacks

    @mitchcasspari

    23 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - Help Net Security https://t.co/O2J5ONx8jJ

    @PVynckier

    23 Aug 2026

    184 Impressions

    2 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Recent CVEs (e.g., CVE-2026-77806, CVE-2026-69836) are actively exploited, impacting network security & potentially compromising data in transit. DNS hijacking, as seen with CubePilot, also poses a critical threat to integrity. #Cybersecurity #News #Vulnerabilities

    @YourAnon_irc

    23 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2026-69836: a CVSS 10.0 unauthenticated RCE inside Entra ID, the service that authenticates your whole org. The fix came with one line: nothing for you to do. You can't patch it, inspect it, or prove it was clean. Trust in the provider is now the control. #EntraID

    @ThisIsSecURL

    23 Aug 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 Microsoft vient de corriger une faille de sécurité qui aurait pu permettre à un hacker d'exécuter du code à distance via le réseau, La vulnérabilité CVE-2026-69836 touchait Microsoft Entra ID, anciennement Azure AD. Microsoft affirme avoir identifié et corrigé la

    @Crypto__Goku

    23 Aug 2026

    5891 Impressions

    4 Retweets

    18 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  13. Unauth RCE in Microsoft Entra ID via deserialization of untrusted data. Attackers send crafted objects over the network with no credentials required to gain code execution. CVE-2026-69836 was found by Robert Fitzpatrick and fixed on August 21 2026. An early advisory wrongly

    @SecureChap

    23 Aug 2026

    99 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Microsoft patched critical Entra ID remote-code-execution vulnerability CVE-2026-69836 (CVSS 10.0) before disclosure; no evidence of exploitation. https://t.co/CW9ewVSsgc

    @MSBIntel

    22 Aug 2026

    866 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  15. Microsoft patched a max-severity Entra ID flaw Thursday (CVE-2026-69836) and confirmed it was exploited. Unauthenticated RCE. Nothing to deploy - it's cloud-side and already mitigated. If you run M365, worth pulling your Entra sign-in and audit logs. https://t.co/4NroUQzRWS

    @NoDramaCyber

    22 Aug 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🔴 Microsoft, Entra ID'deki RCE Açığını (CVE-2026-69836 - CVSS 10.0) Yamaladı. https://t.co/rS3h2Et2lB

    @ridvanyagli

    22 Aug 2026

    202 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. Critical #Microsoft #EntraID Vulnerability CVE-2026-69836 Enables Remote Code Execution #RCE Attacks https://t.co/eel5KTn1ST

    @step9consulting

    22 Aug 2026

    71 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Entra ID ist Identitätskern, nicht Randdienst. Bei CVE-2026-69836 zählt jetzt die Logprüfung. #Microsoft #EntraID #Security #IAM https://t.co/uYxo5i8yjz

    @rohtext_de

    22 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Microsoft confirms CVE-2026-69836, a CVSS 10.0 deserialization RCE in Entra ID, exploited in the wild. Unauthenticated code execution against the identity layer behind M365 and Azure. Redmond says it is fully mitigated. Review your sign-in logs anyway. #InfoSec #ZeroDay

    @infrasecserv

    22 Aug 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. Microsoft says CVE-2026-69836 let unauthenticated attackers execute code in Entra ID and was exploited. It is fully mitigated; no customer action is required. The lesson: cloud-managed does not mean incident-free. #Cybersecurity https://t.co/dumHKz2G3C

    @POTWIRE_

    22 Aug 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CVSS 10.0 Entra ID flaw; actively exploited. CVE-2026-69836: unauth RCE via unsafe deserialization (CWE-502). No auth, no user interaction needed. Microsoft mitigated it server-side, zero customer action required. Exploit method still undisclosed. 🔗 https://t.co/ZUTqqMjQUp

    @exploitgrid

    22 Aug 2026

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Microsoft opravil kritickou chybu v platformě Entra ID (CVE-2026-69836), která umožňovala útočníkům vykonávat kód přes síť. https://t.co/winQBSTT9f

    @rychlofky

    22 Aug 2026

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Microsoft corrigió el aviso de CVE-2026-69836, una vulnerabilidad CVSS 10,0 en Entra ID. Inicialmente figuró como explotada, pero el estado actualizado indica que no hubo ataques reales. Microsoft ya la mitigó y no hay parche que instalar. https://t.co/eQqT9lc5hZ https://t.co/

    @noticiasrazor

    22 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CVSS 10.0 in Microsoft Entra ID (CVE-2026-69836), exploited in the wild. Root cause: deserialization of untrusted data (OWASP A08). Microsoft fixed it service side, no customer action needed. https://t.co/vx0halBwTi #CyberSecurity #AppSec #OWASP https://t.co/hbxcBUG0Ze

    @OWASPHyderabad

    22 Aug 2026

    82 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🛡️ CVE-2026-69836: Vulnerabilidad crítica de deserialización en Microsoft Entra ID con explotación activa Análisis técnico del CVE-2026-69836, vulnerabilidad crítica CVSS 10.0 de deserialización en Microsoft Entra ID con ejecución remota de código. https://t.co/tJeP

    @CiberPlanetaOrg

    21 Aug 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Max-severity Entra ID RCE (CVE-2026-69836) and GitLab CVE-2026-19478 are both under active exploitation, while a poisoned arrayref Rust crate slips build-time malware into the supply chain. #CyberSecurity #BlueTeam #SupplyChain https://t.co/w2LglIfVuf

    @itsalreadywhen

    21 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. Microsoft patches the critical vulnerability CVE-2026-69836 in Entra ID, which had already been exploited. Customers do not need to take any action themselves. https://t.co/UQcmFCK1Nx #Security #Azure #CISA #CVE #EntraID - Follow for more

    @techzine

    21 Aug 2026

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  28. Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) - https://t.co/fGiQYPQAK8 - #Microsoft #EntraID #CVE #vulnerability #Cybersecurity #CyberSecurityNews #SecurityNews https://t.co/zoRnrxrDdM

    @helpnetsecurity

    21 Aug 2026

    593 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836): Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, reportedly exploited in the wild. Entra ID is Microsoft’s cloud identity… https://t.co/ERYZxFHv

    @shah_sheikh

    21 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  30. 🚨 Entra ID'de CVSS 10.0 Açık Aktif İstismar Ediliyor CVE-2026-69836 kodlu kritik açık, Microsoft Entra ID'de uzaktan kod çalıştırılmasına izin veriyor. Microsoft, açığın saldırılarda kullanıldığını doğruladı. #CVE #SiberGüvenlik https://t.co/iBZgGRy6

    @KubbeSiber

    21 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.