Microsoft Entra ID: CVE-2026-69836 patched
Microsoft fixed CVE-2026-69836 in Entra ID, a critical deserialization flaw rated CVSS 10.0. No customer action is needed.
Microsoft fixed CVE-2026-69836 internally in Microsoft Entra ID, a critical remote code execution flaw tied to deserializing untrusted data. The company said the issue was resolved on the server side, published the CVE for transparency, and said customers do not need to take any additional action. Microsoft also corrected the initial exploitation status, which had briefly shown as "Yes" and was later changed to "No".
Microsoft has fixed CVE-2026-69836 internally in Microsoft Entra ID, a critical remote code execution flaw tied to deserializing untrusted data that, according to NVD and other technical analysis, could let an unauthenticated attacker run code over the network. The company said the issue was resolved on the server side, published the CVE for transparency, and said customers do not need to take any additional action.
What kind of flaw is CVE-2026-69836?
It is a CWE-502 weakness, meaning deserialization of untrusted data, within Microsoft Entra ID. NVD describes it as a remote code execution issue, while Rapid7 rated it CVSS 3.1 10.0, critical, with a network attack vector, low complexity, no privileges required, and no user interaction.
The technical data available points to a maximum-severity issue. OpenCVE and Tenable describe it as a critical RCE that an unauthenticated attacker could exploit through serialized data sent over the network. CIRCL also lists the full vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, indicating possible impact to confidentiality, integrity, and availability in a centralized identity service.
What did Microsoft say, and what happened to the exploitation status?
Microsoft, according to a spokesperson cited by The Hacker News, identified and fixed the vulnerability internally in Entra ID, published the CVE for transparency, and said no additional steps are required from customers. SecurityWeek reported the same line, saying the patch was applied on the server side and that users of the service did not need to take action.
The Hacker News also reported that Microsoft’s security advisory initially showed the "Exploited" field as "Yes" before correcting it to "No," making clear that the flaw had not been exploited in the wild. Yahoo Tech interpreted that change as an example of the disclosure challenges around critical identity infrastructure.
What technical and operational scope is attributed to the flaw?
OpenCVE says exact affected Microsoft Entra ID versions were not disclosed, but warns that any deployment without a recent update should be treated as potentially vulnerable until more evidence is available. Dbcve.org says the technical root cause lies in reconstructing objects from attacker-controlled serialized data and recommends as a durable fix avoiding deserialization of untrusted input or restricting it tightly by type and integrity.
Despite the severity, Strix.ai’s technical notice added an EPSS score of 1.37% for exploitation in the next 30 days, suggesting a moderate practical risk at first glance compared with a maximum CVSS rating. Penligent, meanwhile, said it remains an unauthenticated RCE with maximum severity in a critical identity service, although with no verified real-world exploitation at the time of publication.
Feedly said no public proof of concept was available when it published its entry, although it did record reports from several sources about possible exploitation. Vulnerability-Lookup also logged early mentions of exploitation, but that reading was later qualified by Microsoft and The Hacker News after the status was corrected to not known. CybersecurityNews expanded on the possible operational impact by noting that the Entra ID backend is used to authenticate users for Microsoft 365, Azure, and many third-party applications, although no specific Latin America angle was reported in the material reviewed.
Sources
- CVE-2026-69836 (CRITICAL) — details, PoC & remediationdbcve.org· dbcve.org
- CVE-2026-69836: Microsoft Entra Insecure Deserializationstrix.ai· Strix.ai
- CVE-2026-69836 - Exploits & Severityfeedly.com· Feedly
- FKIE_CVE-2026-69836 - Vulnerability-Lookupvulnerability.circl.lu· CIRCL
- CVE-2026-69836 - Vulnerability Detailsapp.opencve.io· OpenCVE
- CVE-2026-69836tenable.com· Tenable
- CVE-2026-69836 - Vulnerability-Lookupvulnerability.circl.lu· Vulnerability-Lookup (CIRCL)
- CVE-2026-69836 Microsoft Entra ID Remote Code Executionpenligent.ai· Penligent
- Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Executionthehackernews.com· The Hacker News
- Microsoft Patches Exploited Entra ID Vulnerability - SecurityWeeksecurityweek.com· SecurityWeek
- Deserialization of untrusted data in Microsoft Entra ID (CVE-2026-69836)rapid7.com· Rapid7
- Critical Microsoft Entra ID Vulnerability Enables Remote ...cybersecuritynews.com· CybersecurityNews
- Microsoft's CVSS 10.0 Entra ID RCE Briefly Tagged ‘Exploited' Before Correction — and What That Reveals About Identity Infrastructure Disclosuretech.yahoo.com· Yahoo Tech
- CVE-2026-69836 Detail - NVD - NISTnvd.nist.gov· NVD (NIST)



