Microsoft disclosed a important distant code execution vulnerability affecting its Entra ID cloud id service.
CVE-2026-69836 acquired a CVSS rating of 10.0 and requires no current privileges or consumer interplay to use.
Microsoft stated it fastened the vulnerability and confirmed it was not exploited within the wild.
Microsoft disclosed a important vulnerability in its Entra ID id platform that would enable an unauthorized attacker to remotely execute code with out current privileges or consumer interplay.
Tracked as CVE-2026-69836, the vulnerability acquired a CVSS rating of 10.0, the best attainable ranking. The flaw impacts Microsoft Entra ID, the corporate’s cloud-based id and entry administration service previously generally known as Azure Energetic Listing.
Myriad: When will OpenAI launch GPT-6? Click on to make your prediction.
Microsoft’s safety advisory says the vulnerability may be exploited over a community with low assault complexity and requires no privileges or consumer interplay.
Deserialization converts information right into a format an utility can use. If the applying doesn’t correctly validate that information, an attacker might manipulate it to execute malicious code.
Microsoft stated it recognized and stuck the vulnerability earlier than publishing the CVE.
“We recognized and addressed this situation with a repair and launched CVE-2026-69836 for higher transparency,” a Microsoft spokesperson informed Decrypt in an announcement. “There are not any extra actions clients have to take.”
Microsoft stated researchers later corrected the vulnerability’s exploitation standing from “Sure” to “No,” confirming it was not exploited within the wild and calling the revision an “informational change solely.” The corporate says the flaw was not publicly disclosed, and exploitation is “much less doubtless.”
Synthetic intelligence has performed an growing function find safety vulnerabilities, with researchers and tech corporations utilizing AI techniques to determine flaws that may in any other case go undetected.
In Might, a safety researcher utilizing Anthropic’s Claude Opus 4.8 found a four-year-old vulnerability in Zcash’s Orchard privateness pool that would have allowed an attacker to create counterfeit ZEC.
Microsoft has additionally been growing AI instruments for vulnerability discovery. In July, the corporate added its MAI-Cyber-1-Flash cybersecurity mannequin to MDASH, a system that makes use of greater than 100 AI brokers to search out and validate software program vulnerabilities.
That very same month, Anthropic disclosed that Claude fashions compromised three corporations throughout inner cybersecurity testing after a configuration error gave the fashions entry to the web.
Each day Debrief E-newsletter
Begin each day with the highest information tales proper now, plus unique options, a podcast, movies and extra.