Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026

    Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher

    September 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider
    • ESMA Flags Crypto Spillover, Prediction Market Risks
    • Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher
    • Tesco alerts police as supermarket becomes latest victim of scam ‘endorsement’ ads | Scams
    • Matt Mullenweg tells (trolls?) Automattic staff, saying he’s back in control after CEO ouster
    • GTA Mod Adds Flock Cameras—And Lets Players Destroy Them
    • 1,400 Yemenis flee to Djibouti within 24 hours | Refugees News
    • Central Eurasia names its 2026 Road to Battlefield winners: Cerberus, WeGlobal AI, and LOOQ
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, September 13
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 22, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 21, 2026Vulnerability / Threat Intelligence

    Update: The story was updated after publication to note that the vulnerability has not been exploited.

    Although the security bulletin originally marked the “Exploited” field under the Exploitability Assessment table as “Yes,” on August 21, 2026, Microsoft corrected the “Exploited” status to “No” after The Hacker News contacted the company for comment. It also noted, “this vulnerability was not exploited in the wild.”

    “We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take,” a Microsoft spokesperson told The Hacker News.

    The headline has been edited to reflect this change. The original story follows below –

    Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required.

    The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was previously called Azure Active Directory or Azure AD.

    “Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft said in an alert released Thursday.

    Flaws of this kind occur when an application converts user-controlled data back into an active object or code structure without proper validation. This can lead to code execution, denial-of-service, or access control bypass that can permit an attacker to perform unauthorized actions.

    Cybersecurity

    The company credited principal security engineer Robert Fitzpatrick for discovering and reporting the issue.

    As of writing, there are currently no details on how the vulnerability has been exploited, when these efforts began and if they are still ongoing, and how it was discovered.

    “This vulnerability has already been fully mitigated by Microsoft,” it added. “There is no action for users of this service to take.”

    Earlier this month, Redmond also patched a high-severity security privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock (CVE-2026-68820, CVSS score: 7.0) that was exploited as a zero-day by the North Korea-linked Lazarus Group as part of a long-running campaign dubbed Operation Dream Job.

    allowing Code CVSS Entra Execution Flaw Microsoft Patches remote severe
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Excel KB5002914 update breaks copy and paste for some users

    Surfshark VPN says hackers breached internal testing, proxy servers

    Conti ransomware gang member sentenced to 4 years in prison

    GitLab urges users to patch max severity path traversal flaw

    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026

    Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher

    September 13, 2026

    Tesco alerts police as supermarket becomes latest victim of scam ‘endorsement’ ads | Scams

    September 13, 2026
    Latest Posts

    Washington’s Badger Mountain Solar Project Canceled by Developer — ProPublica

    August 3, 2026

    Rejected Wisconsin data center proposal had guaranteed tax revenue, housing

    August 3, 2026

    EIG’s MidOcean Energy lines up new investment as NYK spreads its LNG wings

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Scammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email provider

    September 13, 2026

    ESMA Flags Crypto Spillover, Prediction Market Risks

    September 13, 2026

    Think of the parable of a frog in boiling water. That’s us dithering as the ‘unprecedented‘ weather becomes more extreme | Helen Pilcher

    September 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.