Microsoft Patches a Perfect 10 Entra ID Flaw That Was Already Being Exploited

Started by James78, Today at 03:16 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Microsoft Patches a Perfect 10 Entra ID Flaw That Was Already Being Exploited   Views(Read 87 times)
Active members in this topic:
James78(1)

James78

Microsoft has confirmed active exploitation of a maximum severity vulnerability in Entra ID, its cloud based identity platform that used to be called Azure Active Directory. Tracked as CVE-2026-69836, the flaw carries the highest possible CVSS score of 10.0 and stems from a deserialization of untrusted data issue, meaning Entra ID's backend was processing specially crafted data objects without properly validating them first.

The scary part is what this actually enables. An unauthenticated attacker could exploit the flaw over a network to execute arbitrary code, without needing any prior access, any stolen credentials, or any user interaction whatsoever. Given that Entra ID sits at the center of authentication for Microsoft 365, Azure, and a huge number of third party applications, a flaw like this is about as close to a worst case scenario as identity infrastructure gets.

Microsoft says the vulnerability has already been fully mitigated on its own infrastructure and that no customer action is required, which is genuinely good news for anyone relying on the service, but the company has not released details on when exploitation actually began, who was behind it, which organizations were targeted, or how the attack chain worked in practice. That silence is fairly typical for Microsoft's disclosure style, but it does leave defenders with very little to actually hunt for in their own logs.

This is not the first time Entra ID's core has had a brutal year. Back in September 2025 a different critical privilege escalation flaw let a security researcher demonstrate complete access to every single Microsoft Entra ID tenant in the world, and Microsoft patched four other maximum severity vulnerabilities across Azure Arc, Exchange Online, and Azure Managed Instances for Apache Cassandra on the very same day as this latest disclosure.

When the identity layer itself keeps producing perfect 10 vulnerabilities at this pace, it is a genuinely uncomfortable reminder of how much of the modern internet quietly rests on one company's authentication service holding up

Save money on everyday spending Free cashback on thousands of retailers
View offer