Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild

Critical CVE-2026-69836 in Microsoft Entra ID Exploited in the Wild

First seen 21 Aug 2026, 07:20 UTC CybersecuritynewsThehackernewsFeeds.4SysopsTheregisterBleepingcomputer+26 69.9

Article Content

Browse articles
ThreatCluster

Microsoft disclosed a critical remote code execution vulnerability in Entra ID, tracked as CVE-2026-69836, which has been actively exploited in the wild. This flaw, stemming from unsafe deserialization of untrusted data, allows unauthenticated attackers to execute code remotely. The vulnerability was published on August 20, 2026, and is rated CVSS 10.0, indicating maximum severity. Microsoft has fully mitigated the vulnerability on its servers, requiring no action from users. However, the lack of details regarding the exploitation timeline and affected tenants raises concerns among security professionals. Other critical vulnerabilities were also disclosed, including CVE-2026-65801 in Exchange Online, which allows unauthorized privilege escalation. Organizations relying on Entra ID for authentication should review access logs for any anomalies during the exploitation window. No public proof-of-concept or active exploitation was confirmed for other vulnerabilities at the time of disclosure.

Key Points: • CVE-2026-69836 is a critical RCE vulnerability in Entra ID, exploited in the wild. • Microsoft has fully mitigated the vulnerability, requiring no customer action. • Security teams should review logs for anomalies during the exploitation window.

Timeline

2025-09-04
CVE-2025-55241 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-69836 published
Microsoft disclosed a critical RCE vulnerability in Entra ID, allowing unauthenticated code execution.
F4N6
2026-08-20
CVE-2026-65801 published
A critical SSRF vulnerability in Exchange Online was disclosed, allowing privilege escalation.
Threataft
2026-08-20
CVE-2026-65816 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-65770 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-20
CVE-2026-69555 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-21
Active exploitation confirmed
Microsoft confirmed that CVE-2026-69836 was actively exploited before mitigation.
Theregister
2026-08-21
Mitigation deployed
Microsoft reported that the vulnerability in Entra ID has been fully mitigated server-side.
Cybersecuritydive
2026-08-21
CVE-2026-69502 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE