Newsroom
23 August, 2026 / News / AI / Tags: microsoft, cve, vulnerability, exploitation, flaw

A maximum-severity vulnerability in Microsoft’s cloud identity service could have allowed unauthenticated attackers to run code remotely, but the company says it fixed the issue before public disclosure and confirmed no known exploitation
Microsoft has addressed a critical remote code execution vulnerability in its Entra ID cloud identity platform, assigning it the highest possible severity rating under the Common Vulnerability Scoring System. Tracked as CVE-2026-69836, the flaw carries a CVSS score of 10.0 and affects the service formerly known as Azure Active Directory, which underpins authentication for Microsoft 365, Azure and numerous third-party applications used by enterprises worldwide.
The issue stems from the deserialization of untrusted data within Entra ID. Deserialization involves converting stored data into a format an application can process. When validation is insufficient, an attacker can manipulate the data to introduce and execute malicious code over a network. Microsoft’s advisory states that exploitation requires no privileges, no user interaction and only low attack complexity, making the vulnerability particularly severe.
According to details released with the CVE, an unauthorized attacker could theoretically seize control remotely without any prior access to the system. Entra ID serves as the central identity and access management layer for millions of business accounts, which elevates the potential impact of any flaw at this severity level.
The vulnerability was identified by Microsoft Principal Security Engineer Robert Fitzpatrick. Microsoft reported that the company detected and remediated the issue internally before the CVE was published. A company spokesperson stated that the fix had already been applied and that the public release of CVE-2026-69836 was intended solely to provide greater transparency to the security community.
Microsoft confirmed that the flaw has been fully mitigated and that organizations do not need to take any further steps. The company also revised an earlier indication that the vulnerability had been exploited in the wild. After an initial advisory language suggested active exploitation, Microsoft corrected the status to “No,” describing the change as informational only. Officials noted that the issue was never publicly disclosed prior to the advisory, rendering real-world exploitation less likely. No details have been provided on whether any attempts were made, when the underlying condition existed, or how many systems used the specific configuration involved.
The disclosure occurs as both vendors and independent researchers increasingly employ artificial intelligence tools to identify software flaws. Microsoft has integrated its MAI-Cyber-1-Flash cybersecurity model into an internal system known as MDASH, which deploys more than 100 AI agents to locate and validate vulnerabilities. Similar AI-assisted methods have surfaced other significant issues in recent months, underscoring a shift toward automated scanning of large codebases.
While the Entra ID vulnerability itself has been closed, the episode illustrates the high stakes surrounding identity platforms that control access to corporate networks and cloud resources. Microsoft’s decision to issue a CVE after internal remediation aims to inform the wider security community without requiring customer intervention.









