Microsoft fixed a max-severity Entra ID flaw in its cloud, so there is no customer patch for CVE-2026-69836
Microsoft published CVE-2026-69836, a CVSS 10.0 deserialization RCE in Entra ID, its cloud identity service, and says it is already fully mitigated server-side with no action for customers. There is no patch to apply, and Microsoft flipped the advisory's exploitation label from active to none on Friday without explaining the change.

Microsoft published CVE-2026-69836 on August 20, a maximum-severity remote code execution flaw in Microsoft Entra ID, the company's cloud identity and access management service, formerly Azure Active Directory. The advisory rates it CVSS v3.1 10.0. In Microsoft's own words, "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network."
The same advisory says, "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take." BleepingComputer, Help Net Security and Cybersecurity Dive all reported it from Microsoft's MSRC advisory.
The CVE is CWE-502, deserialization of untrusted data, in hosted Entra ID. It is not on-premises Active Directory Domain Services, and it is not a Windows update customers download and install. Microsoft credits the find to its own Robert Fitzpatrick, a principal security engineer. The fix already shipped on Microsoft's side.
The vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H: reachable over the network, low attack complexity, no privileges and no user interaction required, and full confidentiality, integrity and availability impact. The character that pushes it past the usual 9.8 network RCE is S:C, Scope Changed. The vulnerable component and the impacted component are not the same, so a compromise reaches beyond its initial boundary.
That blast radius sits inside Microsoft's identity plane. None of a customer's servers need the update.
Cybersecurity Dive reports that Microsoft's bulletin originally said the flaw was under exploitation, then updated the announcement on Friday to say there was no exploitation, and that the company "did not provide an immediate explanation for the status change." BleepingComputer, working from the earlier bulletin, described a flaw "exploited in attacks," while the walked-back advisory now carries the opposite flag. Exploit code is not public. BleepingComputer notes it is "not yet available online." Microsoft has named no threat actor, no start date and no victim count, and the CVE is not in the CISA Known Exploited Vulnerabilities catalog as of this cycle.
The vulnerable code runs in Microsoft's hosted Entra service, not in a customer tenant. There is no customer-applied update and no exposed-appliance count to chase. The "thousands of exposed instances" framing that fits an internet-facing appliance does not map onto a cloud IAM flaw the vendor fixed on its own infrastructure. That boundary looked different when Fortune 500 tenants were hit in an Azure data-theft campaign, a separate incident where the exposure lived in customer configuration rather than Microsoft's own code.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free