Microsoft sounds alarm over perfect-10 Entra ID flaw

https://image.theregister.com/5211376.jpg?imageId=5211376&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Redmond says the cloud identity bug is already fixed

Updated to add: At the time The Register published this article, Microsoft was telling the public this flaw was being exploited in the wild. It then contacted us after publication to tell us it had "corrected" this CVE’s “Exploited” designation to “No,” saying that (contrary to what it said previously), the flaw was not under attack. Microsoft told us: "This was an informational change only."

Microsoft has fixed a maximum-severity vulnerability in Entra ID.

Tracked as CVE-2026-69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft's cloud identity service. Microsoft disclosed the flaw on Thursday.

Entra ID, formerly known as Azure Active Directory, sits at the heart of identity and access management for Microsoft customers, handling authentication and access to cloud applications and other corporate resources.

According to...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more