Close Menu
NCIJ Network NCIJ Network
    What's Hot

    California lawmaker overcomes pro-Israel spending to win special election | Elections News

    August 22, 2026

    Trump Accounts Get an Unlikely Endorser: Gavin Newsom

    August 22, 2026

    Sonos’ improved Voice Control points to an intriguing smart home future

    August 22, 2026
    Facebook X (Twitter) Instagram
    Trending
    • California lawmaker overcomes pro-Israel spending to win special election | Elections News
    • Trump Accounts Get an Unlikely Endorser: Gavin Newsom
    • Sonos’ improved Voice Control points to an intriguing smart home future
    • Hackers abuse FTP server banners to deliver new Windows malware
    • Bitcoin Year-End Price Outlook: Bitget CEO Weighs In
    • Could these alternative homes be the future in a hotter Britain?
    • Texas Oil and Gas Regulators Will No Longer Have to Accept Public Comment at Open Meetings
    • Is Trump admin allowing sale of protected wild horses to slaughterhouses? What we know
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 22
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft warns of max severity Entra ID flaw exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 21, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks.

    Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across apps and resources.

    Tracked as CVE-2026-69836, this critical security flaw was discovered by Microsoft principal security engineer Robert Fitzpatrick, and it allowed threat actors with no privileges to gain code execution in low-complexity attacks.

    image

    Microsoft says exploit code for CVE-2026-69836 is not yet available online and added that users don’t need to take any action since the flaw has already been fully patched.

    “Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft said in a security advisory published on Thursday.

    “This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.”

    The company didn’t share any additional information, and a Microsoft spokesperson was not immediately available for comment when BleepingComputer asked for more details on attacks exploiting the CVE-2026-69836 flaw.

    Yesterday, Microsoft addressed four more maximum severity flaws, three of them allowing unauthenticated attackers to escalate privileges remotely on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, tracked as CVE-2026-65770, enabled remote code execution on an Azure Managed Instance for Apache Cassandra.

    In September 2025, it patched another critical Entra ID privilege escalation flaw (CVE-2025-55241) reported by Outsider Security security researcher Dirk-jan Mollema that enabled attackers to gain complete access to the Microsoft Entra ID tenant of every company in the world.

    On Friday, CISA also tagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks Entra Exploited Flaw Max Microsoft severity warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers abuse FTP server banners to deliver new Windows malware

    Microsoft rolls out Classic Outlook theme for New Outlook users

    14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

    In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

    Former NSA Director Paul Nakasone Launches National Security Advisory Firm

    New SynkLoader malware pushed in Microsoft Teams phishing campaign

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    California lawmaker overcomes pro-Israel spending to win special election | Elections News

    August 22, 2026

    Trump Accounts Get an Unlikely Endorser: Gavin Newsom

    August 22, 2026

    Sonos’ improved Voice Control points to an intriguing smart home future

    August 22, 2026

    Hackers abuse FTP server banners to deliver new Windows malware

    August 22, 2026
    Latest Posts

    ‘Running Away Balloon’ Artist Sues AI Meme Generator Over Ad Templates

    July 28, 2026

    Hush Security Raises $30 Million for AI Agent Governance

    July 28, 2026

    Armenia’s AI Bet Is Not Chip Manufacturing. It Is Compute Sovereignty 

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    California lawmaker overcomes pro-Israel spending to win special election | Elections News

    August 22, 2026

    Trump Accounts Get an Unlikely Endorser: Gavin Newsom

    August 22, 2026

    Sonos’ improved Voice Control points to an intriguing smart home future

    August 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.