# Microsoft fixes critical Entra ID remote-code-execution flaw

_Saturday, August 22, 2026 at 5:31 PM EDT · Security · Latest · Tier 1 — Major_

![Microsoft fixes critical Entra ID remote-code-execution flaw — Primary](https://cdn.decrypt.co/resize/1024/height/512/wp-content/uploads/2025/05/microsoft-decrypt-style-01-gID_7.png)

Microsoft disclosed and fixed CVE-2026-69836, a critical remote-code-execution vulnerability in its Entra ID cloud identity service. The flaw received a CVSS score of 10.0 and, according to Microsoft's advisory, could be exploited over a network with low attack complexity without existing privileges or user interaction. Microsoft said it identified and addressed the issue before publishing the CVE, and said the vulnerability was not publicly disclosed or exploited in the wild. The company said customers need take no additional action.

## Sources

- [Decrypt](https://decrypt.co/376287/microsoft-perfect-10-exploit-hackers-run-code)

---
Canonical: https://techandbusiness.org/newswire/gn1l-tu7BqeTg-KwR0M5NJ
Retrieved: 2026-08-25T05:37:33.008Z
Publisher: Tech & Business (techandbusiness.org)
