< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-21T11:36:11+05:30

Critical Remote Code Execution Vulnerability in Microsoft Entra ID (CVE-2026-69836) Exploited in the Wild

A critical remote code execution vulnerability (CVE-2026-69836) in Microsoft Entra ID with a CVSS 10.0 score has been actively exploited in the wild, but Microsoft states the issue is fully mitigated without requiring user action.

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.

The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

Read original article

*** END OF TRANSMISSION ***