Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity and access management service and stems from deserialization of untrusted data that can let an attacker execute code over a network. Microsoft says the issue has already been fully mitigated, so no customer action is required.
Related Happenings
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
Vulnerability
H score32
First: 17.06.2026 11:32
Last: 17.06.2026 11:32
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
VulnerabilityAbout this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft My Sign-Ins MFA outage
Service Disruption
H score25
First: 01.06.2026 14:40
Last: 01.06.2026 14:40
Sources 1
About this happening:
Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Microsoft My Sign-Ins MFA outage
Service DisruptionAbout this happening: Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/Mitigation
H score48
First: 14.01.2026 11:38
Last: 14.01.2026 11:38
Sources 1
About this happening:
Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Microsoft Secure Boot certificate expiration guidance for Windows devices
Advisory/MitigationAbout this happening: Microsoft warned that Secure Boot certificates used by most Windows devices expire starting in June 2026, creating a risk that some personal and business systems may n...
Latest development: 10.02.2026 21:06
Microsoft released Windows 10 KB5075912 and continues rolling out replacement Secure Boot certificates to targeted Windows devices through monthly Windows updates, expanding delivery only after devices show sufficient successful update signals ahead of the June 2026 expiration.
Timeline
-
21.08.2026 09:06 2 articles · 2h ago
Microsoft warns of CVE-2026-69836 in Entra ID
Initial DisclosureMicrosoft warned that CVE-2026-69836 in Microsoft Entra ID, previously Azure Active Directory or Azure AD, is a maximum-severity remote code execution flaw caused by deserialization of untrusted data. Microsoft said the flaw had been exploited in the wild, that it was already fully mitigated, and that no customer action is required.
Show sources
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution — thehackernews.com — 21.08.2026 09:06
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution — thehackernews.com — 21.08.2026 09:06