
Microsoft Patches Critical Remote Code Execution Vulnerability in Entra ID
NewsCVEMicrosoft_Entra_IDvulnerabilityvulnerability_disclosure
Microsoft has patched a critical remote code execution vulnerability (CVE-2026-69836) in Entra ID, its cloud identity service formerly known as Azure Active Directory, which was actively exploited in the wild. The flaw, assigned the maximum CVSS score of 10.0, was discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and allows unauthenticated attackers to execute code remotely. Entra ID is used to verify logins and manage access to Microsoft 365, Azure, and third-party applications. The vulnerability was disclosed on August 21, 2026, with no additional technical details on the exploitation mechanism provided.