EXPOSURES › CVE-2026-69836
CVE-2026-69836
HIGH ⌖ ON CISA KEV · EXPLOITEDA deserialization of untrusted data vulnerability in Microsoft Entra ID allowed remote code execution over a network.
An attacker could execute arbitrary code over a network by exploiting a deserialization flaw in Microsoft Entra ID. This failure is critical for DIB organizations because it directly enables remote code execution, bypassing identity and access controls that are foundational to zero-trust architectures. Organizations must ensure Entra ID is patched immediately and monitor for exploitation attempts.
Shame score — A critical remote code execution vulnerability in a core identity service was actively exploited in the wild, indicating a severe lapse in patching and threat detection.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |