Back Feeds.4Sysops CVSS 10 Entra ID flaw was exploited, but Microsoft needs no customer action
Microsoft has disclosed a CVSS 10.0 remote-code-execution vulnerability in Entra ID, its cloud identity service, and confirmed that attackers exploited it in the wild. CVE-2026-69836 has already been fixed within Microsoft’s service, leaving customers with no patches or configuration changes to apply. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
