<- ALL CYBER NEWS

Critical

Entra ID, Azure AD, Identity, RCE, Deserialization, Cloud, CVSS 10

Microsoft Entra ID CVE-2026-69836: CVSS 10.0 RCE

Microsoft Entra ID CVE-2026-69836 is a CVSS 10.0 unauthenticated deserialization RCE in the cloud identity plane. What it means and how to respond.

Microsoft Entra ID CVE-2026-69836 is a maximum-severity, CVSS 10.0 unauthenticated remote code execution flaw in Microsoft's cloud identity service, caused by unsafe deserialization of untrusted data (CWE-502). Microsoft fixed it server-side and states that no customer action is required. It is not listed in CISA's Known Exploited Vulnerabilities catalog and no public proof-of-concept has surfaced, but a code-execution bug at the identity plane is the highest-blast-radius class of cloud vulnerability there is, and the episode is a case study in how little a tenant can independently verify.

Entra ID (formerly Azure AD) is the trust anchor for Microsoft 365, Azure, and thousands of federated SaaS applications that rely on it for single sign-on. An unauthenticated attacker who could execute code in that service would sit above every customer-side control: multi-factor authentication, Conditional Access, and Privileged Identity Management are all enforced by the identity provider, so a compromise at the provider layer can bypass or subvert those customer-side controls. That is why a CVSS 10.0 here reads differently from a 10.0 in a self-hosted app; the affected component is shared infrastructure that customers neither patch nor inspect.

The community reaction fixated less on the bug mechanics than on transparency. Because Microsoft remediated the flaw inside its own platform, customers cannot confirm from their own telemetry whether their tenant was touched during the exposure window, and Microsoft has not published tenant-level hunting guidance or forensic indicators. Defenders drew the obvious comparison to prior identity-plane incidents such as the Storm-0558 signing-key theft, where the gap between "the provider says it is fine" and "we can prove it is fine" was exactly the problem.

Is CVE-2026-69836 being exploited, and what should customers do?

There is no confirmed in-the-wild exploitation, no public PoC, and no CISA KEV listing as of this writing, and Microsoft says the server-side fix requires no customer action. That is genuinely reassuring for the immediate patch question, because there is nothing for a customer to patch. The harder question is assurance: if you cannot patch it, inspect it, or reproduce it, your only lever is to monitor the identity signals you do control. Review Entra sign-in and audit logs for anomalous service-principal and app-registration changes, unexpected credential or federation additions, and token issuance that does not match user behavior, and make sure those logs flow to a SIEM with retention that covers the exposure window.

Attribute

Detail

CVE

CVE-2026-69836

CVSS 3.1

10.0 (Critical)

Weakness

CWE-502 deserialization of untrusted data

Vector

Unauthenticated, network, remote code execution

Affected

Microsoft Entra ID (cloud service)

CISA KEV

Not listed; no public PoC reported

Fix

Server-side by Microsoft, no customer action required

Why does an identity-plane RCE matter more than its CVSS?

Because the blast radius is not bounded by one application. Token-signing, SAML and OAuth claim issuance, and cross-tenant boundaries all live behind Entra ID, so code execution there can, in principle, subvert the cryptographic trust that every downstream app consumes, often without generating the tenant-level audit events defenders rely on. The score caps at 10.0, but the systemic exposure does not, which is precisely why concentration risk in a single cloud identity provider keeps resurfacing in architecture debates.

Our read

The uncomfortable truth of this one is that "no customer action required" and "we are protected" are not the same statement, and only the provider can see the difference. That gap is the whole argument for verifiable by design: where you cannot inspect a control, you compensate by continuously verifying the signals you can observe. For an Entra-dependent estate that means treating identity telemetry as a first-class security surface, exercising your detection and response against forged-token and rogue-service-principal scenarios, and keeping the evidence, so that when a provider quietly fixes a tier-0 flaw you can still detect and prove the presence or absence of downstream abuse: rogue service principals, forged assertions, and anomalous token issuance in your own tenant.

Reporting by The Hacker News and SecurityWeek; CVSS and KEV status per NVD and CISA. Sources linked above.

Related: passkey attacks that bypass phishing-resistant MFA and what CVSS and EPSS miss for prioritization.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.