Microsoft Entra ID Deserialization of Untrusted Data — RCE
Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.
- Vendor
- Microsoft
- Product
- Entra ID (formerly Azure Active Directory)
- CVSS
- 10.0
- EPSS (exploit probability)
- 1.6%
- Status
- kev
- Published
CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID (formerly Azure Active Directory) that allows an unauthenticated, network-adjacent attacker to execute arbitrary code on the service infrastructure. No credentials or user interaction are required.
Microsoft patched it server-side; customers running Entra ID do not need to apply a separate update. CISA added CVE-2026-69836 to the Known Exploited Vulnerabilities catalog on August 21, 2026, with a federal agency compliance deadline of August 24, 2026 under BOD 26-04.
Affected product: Microsoft Entra ID (cloud service — all tenants prior to server-side remediation)
Patch: Applied by Microsoft to service infrastructure; no customer action required to receive the fix
CISA KEV due date: 2026-08-24 (apply mitigations per vendor instructions or document risk-based justification)
Primary sources: Microsoft MSRC advisory · NVD entry · CISA KEV catalog
