Cybersecurity

Microsoft Discloses Exploitation of Critical Vulnerability in Entra ID Platform and Confirms It Has Been Fully Remediated

Microsoft fixed a critical vulnerability with the highest severity level in the Entra ID platform and said attackers exploited it in attacks before additional details were published. The company confirms that remediation has been completed on its end and that no action is required from service users.

2026-08-21
3 min read
10 views
فريق تحرير certi.news
Microsoft Discloses Exploitation of Critical Vulnerability in Entra ID Platform and Confirms It Has Been Fully Remediated

Microsoft fixed a critical security vulnerability in the Entra ID identity and access management platform after confirming that attackers exploited it in attacks. The vulnerability, tracked as CVE-2026-69836, carries the highest severity level and allowed an unauthenticated attacker to execute code remotely through a low-complexity attack.

Entra ID was previously known as Azure Active Directory or Azure AD. The platform provides authentication, policy enforcement, and protection services across applications and resources for Microsoft 365, Azure, and Dynamics CRM Online customers, making any flaw in the identity layer directly relevant to access to the services and resources connected to it.

What Do We Know About the Vulnerability?

Robert Fitzpatrick, a principal security engineer at Microsoft, discovered the vulnerability. According to the company’s security advisory, the flaw resulted from the deserialization of untrusted data within Entra ID, allowing an unauthorized attacker to execute code remotely.

Microsoft said exploit code for the vulnerability is not currently available online, but it did not publish additional information about the nature of the attacks that exploited it. A company spokesperson also provided no further details when BleepingComputer requested comment on the incidents associated with the vulnerability.

No Action Required from Service Users

Microsoft confirmed that the vulnerability has been fully remediated on its end and that Entra ID users do not need to take any steps. The company explained that publishing the CVE identifier is intended to improve transparency regarding the flaw, rather than require customers to install a local update or change service settings.

Why Does This Matter?

The vulnerability is significant because of Entra ID’s position within Microsoft’s cloud environments; the platform handles authentication and enforces access policies across a number of enterprise services. According to the published description, the flaw combined the lack of any requirement for prior privileges with the ability to execute code remotely, while the company did not disclose the attacks’ practical outcomes or the entities that exploited it.

Other Critical Vulnerabilities in Microsoft Services

The disclosure came one day after Microsoft addressed four other vulnerabilities with the highest severity level. Three allowed unauthenticated attackers to escalate privileges remotely in Azure Arc and Exchange Online: CVE-2026-65816, CVE-2026-69555, and CVE-2026-65801. The fourth, CVE-2026-65770, allowed remote code execution in Azure Managed Instance for Apache Cassandra.

In September 2025, Microsoft fixed another critical vulnerability in Entra ID, tracked as CVE-2025-55241, which was reported by security researcher Dirk-jan Mollema of Outsider Security. That vulnerability allowed attackers to gain full access to every company’s Entra ID tenant worldwide, according to the report.

On Friday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component to its catalog of actively exploited vulnerabilities.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news