Critical severity10.0NVD Advisory· Published Aug 20, 2026· Updated Aug 25, 2026
CVE-2026-69836
CVE-2026-69836
Description
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Affected products
1Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836nvdVendor Advisory
News mentions
8- ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and MoreThe Hacker News · Aug 24, 2026
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 StoriesCyber Security News · Aug 23, 2026
- Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgsHelp Net Security · Aug 23, 2026
- Microsoft patches critical Entra ID vulnerability (CVE-2026-69836)Help Net Security · Aug 21, 2026
- Microsoft Patches Exploited Entra ID VulnerabilitySecurityWeek · Aug 21, 2026
- Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code ExecutionThe Hacker News · Aug 21, 2026
- Microsoft Entra ID Remote Code Execution Vulnerability Exploited in the WildCyber Security News · Aug 21, 2026
- Microsoft: 25 Vulnerabilities Disclosed, Including Exploited Entra ID FlawVypr Intelligence · Aug 20, 2026