A CVSS score of 10.0 means every factor an attacker needs lined up at once. Entra ID just handed one out to whoever found it first, and it was not Microsoft.
No login required, no click required
CVE-2026-69836 is a deserialization-of-untrusted-data flaw (CWE-502) in the backend of Microsoft Entra ID, the cloud identity service formerly known as Azure Active Directory. An attacker who sent specially crafted serialized data to a vulnerable endpoint could get it executed as code, with no authentication, no user interaction, and low attack complexity. That combination is what pushes a bug to the maximum possible severity rating, and Microsoft has confirmed it was exploited in the wild before a fix existed.
Fixed, but not explained
Because Entra ID is a service Microsoft operates rather than software customers install, the company was able to patch the vulnerable infrastructure itself. No customer-side update is required, and Microsoft says no public exploit code is currently circulating. That is the good news. The rest of the advisory is notably thin: Microsoft has not disclosed who exploited the flaw, which organisations were targeted, how long the exploitation window was open, or what an attacker was able to do once inside. For a flaw in the system that handles sign-ins, Conditional Access policies, privileged roles, service principals and third-party integrations, that is a lot of unknowns to sit with.
Why the silence matters more here than usual
Entra ID is not one system among many in a typical Microsoft-based environment, it is the one every other system trusts to say who someone is. A deserialization bug at that layer, reachable without credentials, is the kind of flaw that in the wrong hands could touch app access, admin roles and federated logins all at once. Three days ago we covered a separate incident where Fortune 500 employee data was pulled from Azure and Entra tenants, and in that case researchers were clear the cause was stolen credentials on employee endpoints, not a flaw in Azure itself. This time the flaw was in Entra ID’s own backend. European organisations that treated the earlier story as reassurance that “Entra itself is fine” should treat this one as reason to revisit that assumption.
What to check now
There is no patch to deploy, but there is work to do. Review Entra ID sign-in logs and audit trails for the affected window for anomalies you cannot explain, confirm your Conditional Access and privileged role assignments still match what you expect, and check whether any app registrations or service principals were created or modified without a known change ticket behind them. Under NIS2 and GDPR, “the vendor said it’s fixed” is not the same as “we checked.”
If your organisation needs help auditing Entra ID for signs of this exposure or wants a second set of eyes on your identity infrastructure’s blast radius, contact Excello Digital. We help European businesses verify their cloud identity layer is actually as trustworthy as it needs to be, not just assumed to be.
