A maximum severity flaw in the Microsoft identity layer behind Microsoft 365 and Azure lets attackers run code on the network without logging in.
Microsoft disclosed Thursday that a maximum-severity flaw in Entra ID, the cloud identity and single sign-on service that gates Microsoft 365, Azure, and thousands of connected enterprise apps, is being actively exploited in the wild.
The bug, tracked as CVE-2026-69836, scores 10.0 on the Common Vulnerability Scoring System, the scale's ceiling, and lets attackers run code on a target network without logging in via a deserialization flaw. Microsoft says Robert Fitzpatrick discovered it, and the company says it has already shut the hole on its side, with no customer action required. The purpose of the CVE, per Microsoft, is transparency.
Microsoft has not disclosed who is exploiting the flaw, when exploitation started, how many organizations have been hit, or what attackers did after breaking in. Exploit code is not public, according to the MSRC update guide.
The Entra ID advisory lands in a week that already includes four other maximum-severity Microsoft disclosures (CVE-2026-65816, CVE-2026-69555, CVE-2026-65801, and CVE-2026-65770) across Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra. CISA also added a critical Windows IKE Service Extensions RCE to its actively-exploited catalog the same day.
Defenders' next move is to verify that the server-side fix actually covered their tenant, and to ask what Microsoft still has not said about who is already inside.