# Microsoft says Entra ID code-execution flaw was exploited and mitigated

_Friday, August 21, 2026 at 2:06 AM EDT · Security · Breaking · Tier 1 — Major_

![Microsoft says Entra ID code-execution flaw was exploited and mitigated — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEid22xatm4tPGWO1VA9heA8p7i0iK4au3br36QORRasXlUO2uY5836xkZe6gywLOId9oHICopC6jZ8J-di4JI9O3CPOSOGsqoOR4Ps4DrEbKCXSXwMxX_wOGo0fY3zaTW4By4nzbY6jldD58kLAlBYfFxMOEeZOglaQu8R0TtT23Q2jLbQjHwJSoS21pqu5/s1700-e365/entraid.jpg)

Microsoft warned of CVE-2026-69836, a maximum-severity remote-code-execution vulnerability in its Entra ID cloud identity and access-management service, according to an alert cited by The Hacker News. Microsoft said deserialization of untrusted data could let an unauthorized attacker execute code over a network and said the flaw had been exploited in the wild. The company also said it had fully mitigated the issue and that customers need take no action. The report gives no details on the exploitation activity.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html)

---
Canonical: https://techandbusiness.org/newswire/P7eBw-KYoq-RBJjUBVDTjr
Retrieved: 2026-08-21T08:09:48.864Z
Publisher: Tech & Business (techandbusiness.org)
