Microsoft Patches Critical Entra ID and Azure Flaws After False Exploitation Alarm
Microsoft has patched several maximum-severity vulnerabilities affecting Entra ID, Azure Arc, Exchange Online, and an Azure Managed Instance for Apache Cassandra. The most serious flaw, CVE-2026-69836, is a critical deserialization bug in Entra ID that allows an unauthenticated attacker to execute code over a network in low-complexity attacks. The vulnerability is discovered by Microsoft principal security engineer Robert Fitzpatrick.
Alongside the Entra ID fix, Microsoft addresses four additional maximum-severity flaws. Three of them allow unauthenticated attackers to escalate privileges remotely on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801). The fourth, CVE-2026-65770, enables remote code execution on an Azure Managed Instance for Apache Cassandra. Microsoft says no exploit code is available online and that users need to take no action because the flaws are already fully patched.
Microsoft initially flags CVE-2026-69836 as exploited in the wild but later retracts that claim, stating the vulnerability was mistakenly tagged as actively attacked. The company publishes the advisories to provide further transparency. The update follows a September 2025 patch for another critical Entra ID flaw, CVE-2025-55241, which could have granted attackers complete access to the Entra ID tenant of every company in the world.