All incidents

Microsoft Entra ID remote code execution flaw (CVE-2026-69836) exploited in the wild

vulnerabilityopenAug 21, 2026 — Aug 21, 2026
CISA flags Entra ID flaw CVE‑2026‑69836 in KEV list

ON 21 August 2026 the Cybersecurity and Infrastructure Security Agency added CVE‑2026‑69836 to its Known Exploited Vulnerabilities catalogue, signalling that the flaw is being actively exploited.

The vulnerability affects Microsoft Entra ID and permits an unauthenticated attacker to run arbitrary code over the network by abusing insecure deserialization.

CVE‑2026‑69836 carries a CVSS base score of 10.0, rating it Critical, and is classified as a deserialization‑of‑untrusted‑data weakness.

Successful exploitation grants the attacker the same privileges as the Entra ID service, allowing remote code execution without any user interaction.

The flaw resides in the cloud‑only Entra ID platform and does not affect on‑premises Active Directory deployments.

Microsoft has released a security update that addresses the issue, and the patch is applied server‑side so customers do not need to install anything locally.

Details are available in the Microsoft advisory CVE‑2026‑69836 and the broader update guide Microsoft update guide.

The same update cycle also resolved CVE‑2026‑69502, although that flaw has not been added to the KEV list.

The addition to the KEV catalogue confirms that the vulnerability is being exploited in the wild, a conclusion supported by independent reporting from SecurityOnline.

No specific threat actor has been linked to the attacks so far, but the presence in KEV means defenders should treat it as an active risk.

Because Entra ID underpins authentication for many cloud workloads, a compromise could lead to broad lateral movement and privilege escalation.

Organisations should first verify that their Entra ID tenants have received the latest service update, which can be confirmed through the Azure portal or via Microsoft 365 admin centre.

Security teams ought to review sign‑in logs for unusual authentication patterns, especially those involving unexpected token requests or anomalous service principal activity.

Enforcing multi‑factor authentication and restricting legacy authentication protocols can reduce the impact of any stolen credentials that might result from a successful exploit.

Subscribing to the CISA KEV feed and integrating it with vulnerability management tools helps prioritize patches for CVE‑2026‑69836 and similar critical flaws.

After the update is applied, administrators should test authentication flows and conditional access policies to ensure normal operations remain unaffected.

Staying tuned to further Microsoft security advisories will allow rapid response to any newly discovered issues in the identity platform.

Intelligence briefing updated Aug 21, 2026

CVE-2026-69836 10.0 KEV CVE-2026-69502
Root sourcewww.cisa.gov
Timeline Coverage

Swipe to explore timeline