Microsoft has disclosed a maximum-severity remote code execution vulnerability in its cloud-based identity and access management service, Microsoft Entra ID (formerly Azure Active Directory). Tracked as CVE-2026-69836 with a CVSS score of 10.0, the flaw is caused by deserialization of untrusted data, allowing an unauthorized attacker to execute code over a network. Microsoft confirmed the vulnerability has been exploited in the wild but stated that it has been fully mitigated and no customer action is required.
The vulnerability was discovered and reported by Principal Security Engineer Robert Fitzaptrick. As of publication, Microsoft has not disclosed details about the exploitation campaigns, including when they began or if they are ongoing. The company emphasized that the issue is already resolved and users of the service do not need to take any action.
This advisory follows Microsoft’s earlier patch for a high-severity privilege escalation flaw in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS 7.0), which was exploited as a zero-day by the North Korea-linked Lazarus Group in a campaign known as Operation Dream Job.
CVEs: CVE-2026-69836, CVE-2026-68820
Attack groups: Lazarus Group
Companies: Microsoft
Products: Microsoft Entra ID, Windows Ancillary Function Driver for WinSock
Original source: thehackernews.com