Security

Microsoft Sounds Alarm as Perfect-10 Entra ID Vulnerability Is Exploited In the Wild

CVE-2026-69836, an unauthenticated deserialization flaw in Microsoft's cloud identity service, carries a CVSS 10.0 score. Microsoft says the bug is already mitigated and no customer action is required, but is not disclosing who exploited it or how widely.

T
By Tom Reyes Cybersecurity Correspondent
August 21, 2026 / Updated August 25, 2026 / 6 min read

Microsoft has fixed a maximum-severity vulnerability in Entra ID that attackers were already exploiting in the wild. Tracked as CVE-2026-69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft's cloud identity service. Microsoft disclosed the flaw on Thursday along with the unwelcome news that exploitation had already been detected.

How the Flaw Works

According to Microsoft, the vulnerability stems from unsafe deserialization, in which software reconstructs data supplied from an untrusted source without adequately validating it. An attacker could exploit the weakness over a network without an account and — crucially — without persuading a user to click, open or otherwise do anything helpful. "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft's advisory says. That is about as much as Redmond has said about the observed exploitation.

What Microsoft Hasn't Disclosed

The software giant hasn't disclosed who is exploiting CVE-2026-69836, when the attacks began, how widespread they are, or what attackers have done after successfully exploiting the flaw. There are also no public technical details explaining the attack chain, and Microsoft didn't immediately respond to The Register's questions. There is, however, one welcome piece of news for administrators: no customer-deployed patch is required. "This vulnerability has already been fully mitigated by Microsoft," the company said. "There is no action for users of this service to take." Because Entra ID is a Microsoft-operated cloud service, Redmond could fix the vulnerable infrastructure itself rather than ship an update for customers to install.

Why the CVSS Score Is a 10

The CVSS metrics explain the perfect 10: the flaw is remotely exploitable, has low attack complexity, requires neither privileges nor user interaction, and could have a high impact on confidentiality, integrity and availability. Microsoft credited principal security engineer Robert Fitzpatrick with discovering and reporting the vulnerability, although the advisory does not explain how the company detected its exploitation in the wild. Microsoft may have closed the hole, but customers will still want to know who exploited it, what they reached, and how long the activity continued before Redmond shut it down.

Other Identity Bugs Worth Watching

The disclosure comes on top of a heavy August for identity and access-management flaws. On August 19, Citrix warned customers about CVE-2026-19490, an authentication-bypass vulnerability in NetScaler ADC and NetScaler Gateway carrying a CVSS v4.0 score of 9.3. The flaw affects builds 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, and Rapid7 urged organizations to "prioritize patching affected systems on an emergency basis" because Citrix products tend to draw quick exploitation once flaws become public. CVE-2026-19489, a memory-overflow issue rated 8.8, is the second NetScaler bug Citrix patched in the same advisory.

What to Watch Through Year-End

Three checkpoints follow. Microsoft's promised post-mortem on CVE-2026-69836 — likely within 30 to 60 days — will be the first signal of whether the company is willing to disclose attack attribution. Detection telemetry from CrowdStrike, SentinelOne and Elastic showing Entra ID exploitation attempts dating back to when the flaw was first observed will fill in the timeline Microsoft has not. And any post-mortem from Microsoft on the related August 21 CareCloud breach — which the Department of Health and Human Services confirmed affected 3.75 million people via an AWS environment intrusion between March 10 and 16 — will clarify whether identity-layer vulnerabilities are now the leading initial-access vector for healthcare ransomware.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.