Microsoft warns of max severity Entra ID flaw exploited in attacks
Microsoft has patched a maximum-severity vulnerability, designated as CVE-2026-69836, within the Entra ID identity platform that previously allowed unauthorized remote code execution. No user action is required as the company has already mitigated the flaw.