Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-69836

Microsoft Entra ID Deserialization of Untrusted Data — RCE

Deserialization flaw in Microsoft Entra ID allows unauthenticated remote code execution over a network. CVSS 10.0. Actively exploited; added to CISA KEV on August 21, 2026.

cat cve-2026-69836.json
Vendor
Microsoft
Product
Entra ID (formerly Azure Active Directory)
CVSS
10.0
EPSS (exploit probability)
1.6%
Status
kev
Published

CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID (formerly Azure Active Directory) that allows an unauthenticated, network-adjacent attacker to execute arbitrary code on the service infrastructure. No credentials or user interaction are required.

Microsoft patched it server-side; customers running Entra ID do not need to apply a separate update. CISA added CVE-2026-69836 to the Known Exploited Vulnerabilities catalog on August 21, 2026, with a federal agency compliance deadline of August 24, 2026 under BOD 26-04.

Affected product: Microsoft Entra ID (cloud service — all tenants prior to server-side remediation)
Patch: Applied by Microsoft to service infrastructure; no customer action required to receive the fix
CISA KEV due date: 2026-08-24 (apply mitigations per vendor instructions or document risk-based justification)

Primary sources: Microsoft MSRC advisory · NVD entry · CISA KEV catalog