Microsoft sounds alarm as perfect-10 Entra ID flaw comes under attack
Microsoft has fixed a maximum-severity vulnerability in Entra ID that attackers were already exploiting in the wild. Tracked as CVE-2026-69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft's cloud identity service. Microsoft disclosed the flaw on Thursday, along with the unwelcome news that exploitation had already been detected. Entra ID, formerly known as Azure Active Directory, sits at the heart of i
Read more »