1 of 1
Story summary
- Microsoft fully mitigated critical CVE-2026-69836 remote-code execution flaw in Entra ID.
- The vulnerability received a maximum CVSS score of 10.0.
- Robert Fitzpatrick, a principal security engineer, discovered and reported the unsafe deserialization issue.
- Microsoft changed the exploitation status to ‘No’ on August 21, 2026.
- Microsoft gave no details on who exploited the bug, attack timing, or impact.
