Microsoft said a critical remote-code execution vulnerability in Entra ID has been exploited in the wild.
The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has a severity score of 10 out of 10, the highest score possible.
In a bulletin from the Microsoft Security Response Center, Microsoft said the vulnerability has been fully mitigated and no additional action is required of customers. The company added that it disclosed the vulnerability in an effort to provide greater transparency.
Microsoft Entra ID is a cloud-based identity and access management tool. Entra ID became the new name for Azure Active Directory as part of a 2023 rebranding effort.
The company provided no additional details regarding the vulnerability, including the exploitation timeline, specific impacts on customers or details about how the vulnerability was originally discovered.