What happened
Microsoft has confirmed that CVE-2026-69836, a maximum-severity vulnerability in Entra ID, was exploited by attackers before the company fixed it. Entra ID — formerly Azure Active Directory — is the cloud identity service that handles sign-ins and access control for Microsoft 365, Azure, and countless third-party applications. The flaw carries the highest possible CVSS score of 10.0: it stemmed from deserialization of untrusted data and could allow an unauthenticated attacker to execute code remotely, with no user interaction and low attack complexity. It was identified by Microsoft principal security engineer Robert Fitzpatrick. Because Entra ID is a fully managed cloud service, Microsoft rolled the fix out across its own infrastructure — there is nothing for customers to patch — and says it published the CVE for transparency. The company has not shared who exploited the flaw, for how long, or against whom, and no public exploit code was available at the time of reporting.
Why it matters for your business
If your business runs on Microsoft 365, Entra ID is the lock on every door: email, files, Teams, and any app that uses your Microsoft sign-in. A confirmed-exploited, top-severity flaw in that service is worth understanding even when there is nothing to install, because the unanswered questions concern who was targeted before the fix landed. It also illustrates the cloud trade-off in one story: Microsoft fixed the problem fleet-wide without you lifting a finger, but you are relying on the provider's transparency about whether your tenant was affected.
What to do about it
- Review Entra ID sign-in and audit logs for unusual activity, especially on admin accounts, if your licensing retains them.
- Confirm multi-factor authentication and conditional access are enforced for administrators.
- Watch for follow-up guidance from Microsoft in case indicators of compromise are published.
