Microsoft has disclosed and fixed a maximum-severity security flaw in Entra ID, the identity and access management service that sits behind sign-ins for Microsoft 365, Azure, and Dynamics 365 CRM Online. The vulnerability, tracked as CVE-2026-69836, received a CVSS score of 10.0, the highest possible rating, and Microsoft says it was already being exploited in attacks before the company published its advisory on August 21, 2026.
Entra ID, the service Microsoft renamed from Azure Active Directory, is the backbone that verifies who is logging into a huge share of corporate cloud accounts worldwide. A flaw with this severity rating in that system is significant because it does not require an attacker to already have valid credentials or special permissions.
According to Microsoft’s own advisory, the issue stems from what is known as deserialization of untrusted data. In plain terms, some part of the Entra ID service accepted data supplied by an outside party and converted it directly into active code or objects without properly checking it first. Handled incorrectly, this kind of flaw lets an attacker craft malicious input that the system unknowingly executes as if it were legitimate instructions. Microsoft described the result plainly, stating that the flaw allows an unauthorized attacker to execute code over a network, in what the company classified as a low-complexity attack, meaning it would not have required unusual skill or a rare set of circumstances to pull off.
The vulnerability was reported by Robert Fitzpatrick, a principal security engineer at Microsoft. Because Entra ID is a cloud service that Microsoft operates directly, the company was able to deploy a fix on its own infrastructure rather than requiring customers to install a patch themselves. Microsoft’s advisory states that the vulnerability has already been fully mitigated by Microsoft and that there is no action for users of the service to take.
Microsoft has not released details about how the flaw was exploited in the wild, when the attacks began, or whether they are ongoing, and no proof-of-concept exploit code has surfaced publicly as of this writing. The company also has not said how many organizations, if any, were affected before the fix was deployed.
This is not the first serious flaw found in Entra ID this year. In September 2025, researchers disclosed CVE-2025-55241, a separate critical privilege escalation flaw in the same service. Microsoft’s advisory this week also references four other maximum-severity vulnerabilities the company addressed a day earlier, affecting Azure Arc and Exchange Online, underscoring how frequently core Microsoft cloud identity and collaboration services have drawn scrutiny in recent months.
Because the fix was applied on Microsoft’s side, organizations using Entra ID do not need to take any direct action in response to this specific flaw. Security teams may still want to review sign-in and audit logs from the period before the advisory for unusual authentication activity, since Microsoft has confirmed exploitation occurred but has not detailed a specific window or set of indicators.
Source: BleepingComputer, with additional reporting from The Hacker News.
