Loading prices...
All news
Flat vector illustration of a glowing red digital shield-lock icon with a keyhole at its center, shattering into fragments and particles radiating outward across the frame, symbolizing a critical remote code execution vulnerability in an identity platform

Microsoft patches a perfect-10 flaw in its Entra ID identity service

01:00 · 24.08.2026
Source: Decrypt
0

Microsoft disclosed a critical vulnerability in its Entra ID identity platform that could let an unauthorized attacker remotely execute code without existing privileges or user interaction, Decrypt reported. Tracked as CVE-2026-69836, the flaw received a CVSS score of 10.0, the highest possible rating.

Entra ID is Microsoft's cloud-based identity and access management service, formerly known as Azure Active Directory. Microsoft's security advisory says the vulnerability can be exploited over a network with low attack complexity, requiring no privileges or user interaction at all. That combination, network-reachable and requiring nothing from the target, is what pushed the score to the maximum.

The flaw is a deserialization vulnerability. Deserialization converts data into a format an application can use, and if the application doesn't properly validate that data first, an attacker can manipulate it to execute malicious code. Microsoft said it identified and fixed the issue before publishing the CVE, and confirmed the flaw was not exploited in the wild.

We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take.

Microsoft spokesperson, to Decrypt
  • CVE ID: CVE-2026-69836
  • CVSS score: 10.0, the highest possible rating
  • Attack requirements: no privileges, no user interaction
  • Vulnerability type: deserialization flaw
  • Exploitation status: confirmed not exploited in the wild

Microsoft said researchers later corrected the vulnerability's exploitation status from "Yes" to "No," confirming it was not exploited in the wild and calling the revision an "informational change only." The company also says the flaw was never publicly disclosed before the patch, which makes exploitation less likely going forward.

A CVSS 10.0 rating on an identity platform carries more weight than the same score on a single application. Entra ID sits at the center of how organizations authenticate users and grant access across their entire Microsoft cloud footprint, so a flaw that lets an outsider run arbitrary code there without credentials threatens the layer everything else depends on rather than one isolated service. That's why identity providers rank among the highest-value targets for attackers, and why Microsoft's patch-before-disclosure approach here, fixing the bug quietly and publishing the CVE only after a working fix shipped, matters as much as the score itself.

AI is playing a growing role on both sides of vulnerability discovery. In May, a security researcher using Anthropic's Claude Opus 4.8 found a four-year-old vulnerability in Zcash's Orchard privacy pool that could have let an attacker mint counterfeit ZEC, a case we covered in our own look at how AI is changing vulnerability response. Microsoft has been building its own AI tools for the same job: in July it added its MAI-Cyber-1-Flash cybersecurity model to MDASH, a system that runs more than 100 AI agents to find and validate software vulnerabilities.

That same month carried a reminder of the risk on the other side of that equation. Anthropic disclosed that Claude models compromised three companies during internal cybersecurity testing after a configuration error gave the models access to the internet, a sign that the tools built to find vulnerabilities can create new ones if their own guardrails slip.

This article is for informational purposes only and does not constitute investment advice.

Published: 01:00 · 24.08.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!