HomeSecurityHackers exploit critical RCE vulnerability in Microsoft Entra ID

Hackers exploit critical RCE vulnerability in Microsoft Entra ID

Microsoft has disclosed a critical vulnerability in Microsoft Entra ID with a CVSS score of 10.0 — the highest possible — that has already been exploited by hackers. The vulnerability, tracked as CVE-2026-69836 , could allow an unauthenticated attacker to execute code remotely over a network without requiring a valid account. Microsoft said the vulnerability has already been fully addressed by the company, with no action required from users or administrators.

CVE-2026-69836 critical vulnerability Microsoft Entra ID CVSS 10.0

Microsoft Entra ID, formerly known as Azure Active Directory or Azure AD, is Microsoft's central cloud identity and access management service. It acts as the "control layer" for Microsoft 365, Azure , and hundreds of connected SaaS applications, making any vulnerability in it extremely dangerous. The disclosure was made on August 20, 2026, with public reports confirming that Microsoft had already fixed the problem in its infrastructure.

According to The Hacker News, the technical cause of the vulnerability is a deserialization flaw: the service was processing serialized objects controlled by the attacker without proper validation, allowing code execution over the network. Such flaws, known as CWE-502, can lead to code execution, denial of service, or access control bypass.

See also: Microsoft Patch Tuesday August 2026: 421 CVEs and active zero-day in Windows

CVE-2026-69836: What we know about the Microsoft Entra ID vulnerability

Microsoft said in its announcement: “Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.” The company attributed the discovery and reporting of the vulnerability to Robert Fitzaptrick, Principal Security Engineer. So far, there are no publicly available details about how the exploit was exploited, when these efforts began, or whether they are still ongoing.

CVE -2026-69836 stands out for several reasons. First, the CVSS score of 10.0 is the maximum possible, indicating maximum severity. Second, no valid account is required for exploitation — an unauthorized attacker can exploit the vulnerability directly over a network. Third, Microsoft Entra ID is central to authentication, authorization, and access tokens across entire cloud environments, meaning that a successful exploitation could have a huge impact.

Microsoft publicly disclosed the number of affected customers or tenants, nor any financial losses related to CVE-2026-69836.

CVE-2026-69836 critical vulnerability Microsoft Entra ID CVSS 10.0

Microsoft Entra ID: The new battlefield for cybercriminals

The CVE-2026-69836 vulnerability is part of a broader pattern of attacks on identity platforms, where cloud identity is treated as the “control layer” for entire ecosystems. In July 2026, Microsoft reported CaptiveCrunch linked to the Midnight Blizzard, including adversary-in-the-middle phishing that again involved Microsoft Entra ID.

Also in August 2026, researchers disclosed a separate Entra ID vulnerability , CVE-2026-62869 , a CVSS 8.8 spoofing flaw that Microsoft also addressed without requiring a customer update. Another disclosure that same month described a Windows Hello for Business key abuse , where malware in a connected session could authenticate to the Microsoft Entra ID and enroll devices controlled by the attacker.

See also: Hackers target Microsoft Entra accounts via device code phishing

These incidents reveal a strong trend for 2026: attackers are focusing on authentication flows and token, rather than exploiting only on-premises software flaws. This shift makes cloud identity services, such as Microsoft Entra ID, prime targets for sophisticated threat actors.

Earlier this month, Microsoft also patched a serious privilege escalation vulnerability affecting the Windows Ancillary Function Driver for WinSock ( CVE-2026-68820 , CVSS 7.0 ), which was used as a zero-day by the North Korea -linked Lazarus Group as part of a long-running campaign dubbed Operation Dream Job . This highlights that both state actors and cybercriminals are actively targeting Microsoft infrastructure .

Security analysts point out that identity errors can be particularly serious because they can bypass MFA, Conditional Access , and logging, showing how cloud identity failures can become “perfect crime” scenarios in practice.

Adobe Campaign Classic CVE-2026-48449 critical vulnerability CVSS 10.0 arbitrary code execution

How to protect yourself from Microsoft Entra ID vulnerabilities

Although CVE-2026-69836 does not require any action from customers, the vulnerability is a powerful reminder of the need for strong identity security. Organizations should monitor Microsoft Security Response Center and security alerts for any subsequent guidance or forensic analysis indicators. It is also recommended to review identity security controls in general: MFA, Conditional Access, device enrollment policies, and privileged access governance remain critical.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Adobe Campaign Classic: Critical CVSS 10.0 vulnerability allows unauthenticated code execution (CVE-2026-48449)

Specifically, administrators should review recent logins, device registrations, OAuth , and unusual token, especially if their environment has been exposed to phishing, device password abuse, etc.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS