Microsoft has patched a maximum-severity vulnerability in its Entra ID identity and access management platform that has already been exploited in attacks. The flaw, tracked as CVE-2026-69836, was discovered by Microsoft principal security engineer Robert Fitzpatrick and affects Entra ID, the cloud-based service formerly known as Azure Active Directory that provides authentication and policy enforcement for Microsoft 365, Azure, and Dynamics CRM Online customers. According to Microsoft, the vulnerability allowed threat actors with no privileges to achieve code execution in low-complexity attacks.

Microsoft said exploit code for CVE-2026-69836 is not yet publicly available, and the company has stated that users do not need to take any action because the flaw has been fully mitigated. In a security advisory published Thursday, Microsoft described the issue as a deserialization of untrusted data in Entra ID that permits an unauthorized attacker to execute code over a network. The company added that the purpose of the advisory is to provide transparency, as the vulnerability has already been addressed on the service side. Microsoft did not share additional technical details about the attacks, and a spokesperson was not immediately available for comment when asked for more information.

The Entra ID patch comes alongside fixes for four other maximum-severity flaws that Microsoft addressed the same day. Three of those flaws allowed unauthenticated attackers to remotely escalate privileges on Azure Arc, tracked as CVE-2026-65816 and CVE-2026-69555, and on Exchange Online, tracked as CVE-2026-65801. The fourth, tracked as CVE-2026-65770, enabled remote code execution on an Azure Managed Instance for Apache Cassandra. These patches reflect ongoing efforts to secure Microsoft鈥檚 cloud infrastructure, which is widely used by U.S. enterprises and government agencies.

This is not the first critical Entra ID issue Microsoft has dealt with recently. In September, the company patched another critical privilege escalation flaw in Entra ID, tracked as CVE-2025-55241, which was reported by security researcher Dirk-jan Mollema of Outsider Security. That vulnerability could have allowed attackers to gain complete access to the Entra ID tenant of every company using the platform worldwide, underscoring the importance of identity systems as a prime target for malicious actors.

The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, also flagged a separate critical remote code execution flaw in the Windows Internet Key Exchange Service Extensions component as actively exploited on Friday. That designation typically triggers federal agency patching requirements and highlights the broader threat landscape for identity and network services. Microsoft鈥檚 handling of the Entra ID flaw, with no user action required, reflects the nature of cloud-hosted services where patches are applied centrally rather than on individual machines.

The company鈥檚 advisory did not disclose how widespread the attacks were or which specific customers may have been affected. Microsoft鈥檚 guidance remains that no action is needed from users of Entra ID, as the service has already been fully patched. For U.S. organizations relying on Microsoft鈥檚 cloud platform, this incident serves as a reminder that identity and access management systems remain a high-value target for attackers seeking initial entry into corporate networks.

More cybersecurity news from TechManNews.