# Microsoft fixes critical Entra ID remote-code-execution flaw

_Published Monday, August 24, 2026 at 11:28 PM EDT · Security · Latest · Tier 1 — Major_

![INTERNET hacking microsoft artificial intelligence AI cybersecurity Windows — Primary](https://cdn.decrypt.co/resize/1024/height/512/wp-content/uploads/2025/05/microsoft-decrypt-style-01-gID_7.png)

Microsoft disclosed and fixed CVE-2026-69836, a critical remote-code-execution vulnerability in its Entra ID cloud identity service. The flaw received a CVSS score of 10.0 and, according to Microsoft's advisory, could be exploited over a network with low attack complexity without existing privileges or user interaction. Microsoft said it identified and addressed the issue before publishing the CVE, and said the vulnerability was not publicly disclosed or exploited in the wild. The company said customers need take no additional action.

## Sources

- [Decrypt](https://decrypt.co/376287/microsoft-perfect-10-exploit-hackers-run-code)

---
Canonical: https://techandbusiness.org/newswire/gn1l-tu7BqeTg-KwR0M5NJ
Published: 2026-08-25T03:28:20.952Z
Story chronology: 2026-08-22T21:31:03.000Z
Retrieved: 2026-10-10T02:45:27.467Z
Publisher: Tech & Business (techandbusiness.org)
