Microsoft has addressed a critical remote code execution vulnerability impacting its cloud identity service, Entra ID, which has been actively exploited in the wild.
Tracked as CVE-2026-69836 and assigned the maximum CVSS score of 10.0, the security flaw involves an issue with the deserialization of untrusted data. The vulnerability was originally discovered by Microsoft Principal Security Engineer Robert Fitzpatrick and allows an unauthenticated attacker to execute code over a network within Microsoft’s cloud identity platform.
“Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft stated in its advisory.
Entra ID, formerly known as Azure Active Directory, serves as Microsoft’s core cloud-based identity and access management service, verifying user logins and governing access across Microsoft 365, Azure, and integrated third-party applications.
Despite the critical severity rating and confirmation of in-the-wild exploitation, administrators and enterprise customers are not required to take any manual remediation steps. According to Microsoft, the vulnerability resides entirely within cloud-managed components and has already been fully mitigated.
“This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency,” the company explained.
As of press time, Microsoft has not released details regarding the threat actors behind the exploitation, the exact timeline of the attacks, the scope of affected organizations, or the specific post-exploitation activities conducted by attackers.