Microsoft has patched several maximum-severity vulnerabilities affecting Entra ID, Azure Arc, Exchange Online, and an Azure Managed Instance for Apache Cassandra. The most serious flaw, CVE-2026-69836, is a critical deserialization bug in Entra ID that allows an unauthenticated attacker to execute code over a network in low-complexity attacks. The vulnerability