Microsoft patched a maximum severity security vulnerability in its Entra ID platform, formerly known as Azure Active Directory. The flaw, tracked as CVE-2026-69836, allowed unprivileged attackers to execute code remotely.
Microsoft confirmed that hackers exploited the vulnerability in active attacks. The company fully mitigated the flaw on its end, requiring no action from service users.
The patch was part of a broader security update addressing 22 vulnerabilities across various Microsoft products. This update included several other critical remote code execution and privilege elevation flaws within Azure and other services.