Microsoft fully mitigates a CVSS 10.0 Entra ID flaw and corrects the exploited flag
CVE-2026-69836 is an unsafe-deserialization bug in Entra ID rated CVSS 10.0, allowing unauthenticated remote code execution over the network with no privileges or user interaction. Microsoft said the cloud service is already fully mitigated and later changed the Exploited flag from yes to no.

On August 21 The Register reported CVE-2026-69836, an unsafe-deserialization vulnerability in Microsoft Entra ID scored CVSS 10.0. The bug allowed unauthenticated remote code execution over the network, with no privileges and no user interaction required.
What we know
- CVE-2026-69836 is an unsafe-deserialization flaw in Entra ID with a CVSS score of 10.0.
- It allowed unauthenticated remote code execution over the network, with no privileges and no user interaction.
- Microsoft said the cloud service was already fully mitigated and customers need take no action.
- The company later corrected the Exploited flag from yes to no.
- The report credited Robert Fitzpatrick.
Takeaways
- A perfect-10 Entra ID bug was treated as a cloud-side fix, not a customer patch.
- Microsoft walked back the Exploited flag after first marking the issue as exploited.
- The finding is credited to Robert Fitzpatrick.
Source: The Register


