Security3 min read
Microsoft fully mitigates a CVSS 10.0 Entra ID flaw and corrects the exploited flag
CVE-2026-69836 is an unsafe-deserialization bug in Entra ID rated CVSS 10.0, allowing unauthenticated remote code execution over the network with no privileges or user interaction. Microsoft said the cloud service is already fully mitigated and later changed the Exploited flag from yes to no.
