Microsoft Entra ID vulnerability scores a perfect 10.0 severity rating

NewsSat, 22 Aug 2026 23:01:54 UTC2 hours ago
Microsoft Entra ID vulnerability scores a perfect 10.0 severity rating

Microsoft has patched one of the most severe security flaws it has disclosed this year, a critical remote code execution bug in Entra ID, the cloud identity system that verifies logins for millions of business accounts. The Microsoft Entra ID vulnerability, tracked as CVE-2026-69836, carries a maximum CVSS score of 10.0, meaning an attacker with no existing access and no need for user interaction could theoretically seize control remotely. Microsoft says the flaw has already been fixed and was not exploited in the wild, though the path to that conclusion involved a notable correction.

Key takeaways

  • Microsoft disclosed a critical remote code execution flaw in Entra ID, tracked as CVE-2026-69836, with the highest possible CVSS score of 10.0.
  • The bug stemmed from deserialization of untrusted data and required no privileges or user interaction to exploit.
  • Microsoft said it had already fixed the issue before publishing the advisory and confirmed there is no action for customers to take.
  • An early report suggested active exploitation, but Microsoft later corrected that status, calling the change purely informational.
  • Security engineer Robert Fitzpatrick discovered the flaw, which arrives amid a broader industry shift toward AI-assisted vulnerability hunting.

Critical Microsoft Entra ID Remote Code Execution Vulnerability

CVE-2026-69836 is about as serious as software flaws get, sitting at the top of the CVSS scale with a perfect 10.0 rating. Entra ID, formerly known as Azure Active Directory, is the backbone identity service behind Microsoft 365, Azure, and countless connected third-party applications, which is exactly why a flaw at this severity level draws attention across the security industry.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related