Microsoft Patches a Maximum-Severity Flaw in Entra ID
CVE-2026-69836 scored a perfect 10.0 for severity and could have let an attacker run code in Microsoft's cloud identity service without logging in. Microsoft says it's already fixed and there's nothing users need to do.
Meridians Money Desk
Published 23 August 2026 · Updated 23 August 2026 · 3 min read
SoftwareThe short answer
- Microsoft disclosed CVE-2026-69836, a maximum-severity (CVSS 10.0) remote code execution flaw in Entra ID, the cloud identity service behind sign-ins for Microsoft 365, Azure and many third-party apps.
- The bug stemmed from deserialization of untrusted data and could let an unauthenticated attacker execute code over the network, according to security researchers.
- Microsoft initially flagged the flaw as exploited in the wild, then corrected that assessment on August 21, 2026, saying it was not exploited before the fix shipped.
- Microsoft says the issue is fully mitigated on its end and there is no action for individual users to take.
Microsoft has patched a maximum-severity vulnerability in Entra ID, the cloud identity service that handles sign-ins for Microsoft 365, Azure and a wide range of third-party apps. The flaw, tracked as CVE-2026-69836, scored a perfect 10.0 on the industry's severity scale.
What the flaw did
The vulnerability involved deserialization of untrusted data in Entra ID, which could let an unauthenticated attacker execute code over the network — no password or login required. It was discovered by security researcher Robert Fitzpatrick and disclosed publicly on August 21, 2026.
Was it actually exploited?
Microsoft initially marked the vulnerability as exploited in the wild, then revised that assessment on August 21, stating it had not in fact been exploited before the patch was deployed. The company has not published details on the exploitation timeline or how the initial assessment was made.
What Microsoft says to do
Because Entra ID is a cloud service, Microsoft fixed the flaw on its own infrastructure rather than through a downloadable patch. The company says there is no action required from individual users or IT administrators for this specific vulnerability.
Sources
Every factual claim above is traceable to these documents. Check them — that is why they are here.
About this byline
Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.
Sponsored
Paid placement · not editorial
CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.
4 min read · 13 September 2026
Microsoft's September Patch Fixes Two Windows Flaws Already Under Attack
4 min read · 9 September 2026
Google Confirms Active Attacks Exploiting a Chrome Flaw. Patch Now, Then Check Every Chromium Browser You Use
3 min read · 6 September 2026
The Meridians Brief
One considered email a week
What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.
Sign-up opens with our launch issue. Nothing is sent or stored yet.
