Microsoft disclosed a critical remote code execution flaw in Entra ID tracked as CVE-2026-69836 and confirmed it was exploited in the wild. The vulnerability, rated CVSS 10.0, is a CWE-502 deserialization of untrusted data issue that could let an unauthenticated attacker send crafted serialized input to a vulnerable endpoint and execute arbitrary code without user interaction. Microsoft credited Principal Security Engineer Robert Fitzaptrick with reporting the bug, but did not release technical details about the exploitation chain, timeline, or discovery circumstances.
Because Entra ID underpins authentication and access control across Microsoft 365, Azure, and many third-party applications, successful exploitation could have enabled broader cloud compromise, including token theft or policy manipulation. Microsoft said the managed cloud service was fully remediated server-side, so customers do not need to deploy patches, but advised organizations to review Entra ID sign-in logs, conditional access policies, and privileged role assignments for suspicious activity that may have occurred before the fix. The flaw aligns with OWASP guidance on unsafe deserialization, which warns that attacker-controlled serialized data can trigger denial-of-service, authorization bypass, data integrity issues, and arbitrary code execution through gadget chains.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
On August 21, 2026, Microsoft reversed its earlier statement that CVE-2026-69836 in Entra ID had been exploited in the wild and updated the CVE entry's exploitation field from "Exploited" to "No." Microsoft said the change was informational only and maintained that the vulnerability had already been fully mitigated.
On August 21, 2026, CISA added Microsoft Entra ID flaw CVE-2026-69836 to its Known Exploited Vulnerabilities catalog. The listing created public tension with Microsoft's later clarification that exploitation in the wild was not confirmed.
On August 20, 2026, Microsoft disclosed CVE-2026-69836, a critical CVSS 10.0 remote code execution flaw in Microsoft Entra ID caused by deserialization of untrusted data, and confirmed it had been exploited in the wild. Microsoft credited researcher Robert Fitzpatrick for reporting the issue.
OWASP cites CVE-2011-2092 in Adobe BlazeDS AMF deserialization as a real-world example of CWE-502, where attacker-controlled classes and properties could be deserialized to trigger harmful behavior on the target server.
Microsoft said the Entra ID vulnerability had already been patched and fully mitigated on the managed cloud service, with no customer patches or configuration changes required. The company said the disclosure was made for transparency and advised customers to review logs, conditional access policies, and privileged role assignments for suspicious activity predating the fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethecyberthrone.in
Open sourcethreataft.com
Open sourcereddit.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceowasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.