
Microsoft has disclosed and fully patched a maximum-severity vulnerability in its Entra ID cloud identity platform that attackers were already exploiting before the fix shipped. Tracked as CVE-2026-69836 with a CVSS score of 10.0, the flaw stems from deserialization of untrusted data, allowing an unauthorized attacker with no privileges to execute arbitrary code over the network in a low-complexity attack. The bug was discovered by Microsoft principal security engineer Robert Fitzpatrick.
The good news is that Microsoft has already silently mitigated the vulnerability on the service side. In its advisory, the company stated: “This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take.” The disclosure is described as a transparency measure, and neither enterprises nor individual users need to apply any patch or configuration change. A similar critical Entra ID privilege escalation flaw (CVE-2025-55241) was patched in September 2025, making this two back-to-back serious issues with Microsoft’s cloud identity infrastructure.
