
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Ex
Key Highlights
- "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft said in an alert released Thursday.
- Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment.
- 0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service.
- "This vulnerability has already been fully mitigated by Microsoft," it added.
-
- that was exploited as a zero-day by the North Korea-linked Lazarus Group as part of a long-running campaign dubbed Operation Dream Job.
Ravie LakshmananAug 21, 2026Vulnerability / Threat Intelligence Update: The story was updated after publication to note that the vulnerability has not been exploited.
Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment.
It also noted, "this vulnerability was not exploited in the wild.
" The headline has been edited to reflect this change.
The original story follows below - Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.
The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.
0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service.
It was previously called Azure Active Directory or Azure AD.
"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft said in an alert released Thursday.
Flaws of this kind occur when an application converts user-controlled data back into an active object or code structure without proper validation.
This can lead to code execution, denial-of-service, or access control bypass that can permit an attacker to perform unauthorized actions.
The company credited principal security engineer Robert Fitzpatrick for discovering and reporting the issue.
As of writing, there are currently no details on how the vulnerability has been exploited, when these efforts began and if they are still ongoing, and how it was discovered.
"This vulnerability has already been fully mitigated by Microsoft," it added.
"There is no action for users of this service to take.
" Earlier this month, Redmond also patched a high-severity security privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.
- that was exploited as a zero-day by the North Korea-linked Lazarus Group as part of a long-running campaign dubbed Operation Dream Job.
Found this article interesting?
Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
__Ravie Lakshmanan__Aug 21, 2026Vulnerability / Threat Intelligence
Originally reported by The Hacker News. TechVeb news desk.
Stay in the loop
Get the latest tech news and AI insights delivered to your inbox. No spam, unsubscribe anytime.
TechVeb Team
Your trusted source for the latest in technology, AI innovations, and digital trends. We bring you in-depth analysis, expert reviews, and comprehensive guides.
Learn more about us →More cybersecurity News
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.
Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal securit
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in ques

