Microsoft says attackers already exploited a maximum-severity bug in Entra ID, its cloud identity service, before the company shut the door on it. The flaw, tracked as CVE-2026-69836 and rated 10.0 on the CVSS scale, allowed remote code execution through deserialization of untrusted data.
Entra ID, formerly Azure Active Directory, handles logins and access control for Microsoft 365, Azure, and third-party apps. An advisory issued Thursday warned that an unauthorized attacker could execute code over the network without authentication.
Microsoft credited principal security engineer Robert Fitzpatrick for reporting the issue and said the service has been fully mitigated. The company stressed that no customer action is required and that the advisory exists purely for transparency. It declined to say who exploited the flaw, when the attacks began, how many organizations were affected, or what the intruders did once inside.
Deserialization bugs convert user-controlled data back into active objects without proper validation, which can lead to code execution, denial-of-service, or access-control bypass. This is the second high-profile Microsoft identity issue in recent weeks: earlier this month the company patched a Windows privilege-escalation zero-day (CVE-2026-68820) used by North Korea’s Lazarus Group in its Operation Dream Job campaign.
Admins should verify that conditional access and sign-in logs cover the service while the investigation continues, though Microsoft says there is nothing left to patch on the customer side.
