Microsoft has patched a maximum-severity vulnerability, tracked as CVE-2026-69836, in its Entra ID platform that allowed unauthorized remote code execution.
The flaw, discovered by principal security engineer Robert Fitzpatrick, carried a CVSS severity score of 10.0 and was exploited in real-world attacks before the fix.
While the cloud-side mitigation is complete, Microsoft has not yet disclosed the identities of the attackers or confirmed if specific customer data was compromised.