ON 21 August 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE‑2026‑69836 to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects Microsoft Entra ID (formerly Azure Active Directory) and is named the Microsoft Entra ID Deserialization of Untrusted Data Vulnerability. It allows an unauthenticated attacker to execute arbitrary code over the network by exploiting insecure deserialization.
CVE‑2026‑69836 is a deserialization‑of‑untrusted‑data vulnerability. Successful exploitation enables remote code execution with the privileges of the Entra ID service. The Common Vulnerability Scoring System assigns it a base score of 10.0, rating it Critical. Microsoft has released a security update that addresses the issue.
Because the entry appears in the KEV catalogue, active exploitation in the wild has been confirmed. No public reports link this vulnerability to ransomware campaigns at this time. CISA has set a remediation deadline of 24 August 2026 for Federal Civilian Executive Branch (FCEB) agencies to apply the required mitigations.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritising Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements”. Follow applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26‑04 patching guidelines.
This directive binds FCEB agencies; all other organisations should review their exposure to Entra ID and implement the vendor’s patch or mitigations as a precaution.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-69836 and the CISA KEV catalogue.