
MICROSOFT has released 22 security updates covering Azure Entra ID and Exchange, fixing critical flaws including a CVSS 10 remote code execution bug in Entra ID that was already being exploited.
The most severe issue tracked as CVE-2026-69836 scores a perfect 10 on the CVSS scale and allows remote code execution without user interaction due to unsafe data processing in the Entra ID service. Microsoft confirmed the flaw was being used in the wild and applied a server‑side patch that requires no action from customers. A second vulnerability CVE-2026-69502 affects an unspecified component and is listed with no CVSS score but is also addressed in the same update rollout.
Other patches in the release resolve elevation of privilege and remote code execution weaknesses in Azure and Exchange, several of which are rated 10/10. Microsoft said it is also preparing fixes for the ShieldBreak exploit chain which carries a CVSS score of 7.8. Additionally a command injection vulnerability discovered in Copilot has been remedied as part of this month’s bundle.
The active exploitation of CVE-2026-69836 shows that attackers are moving quickly to abuse cloud identity services before mitigations are widely deployed. No specific threat actor has been linked to the activity but the flaw’s wormable nature means any unprotected tenant could be at risk.
Because Microsoft applied the fixes on its backend most organisations will not need to deploy client side updates for the Entra ID issue. Nevertheless administrators should verify that conditional access policies are enforced and that sign‑in logs are reviewed for anomalous authentication attempts.
Defenders should also check that Exchange servers have received the latest cumulative updates and that any Copilot integrations are running the patched version. Monitoring for unexpected admin role changes and reviewing audit logs for privilege escalation attempts will help catch any post‑exploitation activity. Keeping hybrid environments synchronized with the latest security baseline remains the most effective way to limit exposure to these flaws.