COMPANIES

Microsoft Entra ID flaw under attack after critical bug found

Microsoft

Microsoft fixes critical Entra ID flaw rated perfect 10 after security scare.

Microsoft Entra ID has faced a major security scare after a critical bug was found in the cloud service. The flaw earned a perfect 10 score, but Microsoft says it has already fixed the issue.

Microsoft hit with a perfect 10 security flaw

The bug is tracked as CVE-2026-69836. It affects Microsoft Entra ID, the cloud service used by companies to manage logins and access. As reported by The Register, the flaw received a CVSS score of 10.0. That is the highest possible rating. The bug could let an attacker run code on Microsoft’s systems from afar. The problem came ‘unsafe deserialization’. In simple terms, the service could handle data from an untrusted source in an unsafe way.

The risk was high because an attacker did not need an account or special access. A user did not need to click a link or open a file. The attack can run over a network. That made the flaw especially serious. Entra ID sits at the heart of many Microsoft cloud services. It handles identity and access for users and organizations. Microsoft said the flaw had been fully fixed. The company also said customers did not need to take extra action. Robert Fitzpatrick, a Microsoft principal security engineer, was credited with finding the flaw and fixing it.

Confusion over active attacks

The story became more confusing after Microsoft changed the status of the flaw. The first security notice said the bug was being exploited. That suggested hackers were already using it in attacks. Microsoft later contacted the publication and said it had corrected the โ€œExploitedโ€ label to โ€œNoโ€. The company said this was an informational change. Microsoft’s updated notice said there was no exploitation. The company did not give a detailed reason for the change.

However, some questions went unanswered. Microsoft has not shared details about an attack method, possible victims or the timeline behind the discovery. The flaw was serious enough to allow remote code execution. However, there is no public technical detail showing how attackers could use the bug. The changing status is important because active exploitation would make the issue more urgent for security teams. At the same time, the fix means the vulnerable service has already been secured by Microsoft.

Microsoft

What users need to know

There is some good news for organizations using Entra ID. They do not need to download a special patch for this flaw. As reported by Yahoo Tech, Microsoft confirmed that the maximum-severity bug had been addressed in its own cloud systems. This is possible because Entra ID is a managed service. Microsoft said the vulnerability had already been fully mitigated. Users therefore do not need to install an update or change a setting because of this specific flaw.

Still, the case shows why cloud security matters. Entra ID controls access to important business tools and data. A serious weakness in such a service could have wide effects. For now, Microsoft says the problem is fixed. The bigger issue is the lack of clear public detail about what happened before the fix.

Authorโ€™s Opinion

A perfect 10 flaw in a key cloud service is always worrying. The good part is that Microsoft fixed it without asking customers to act. The changing attack status, though, shows why clear and timely security updates matter.

READ MORE: Apple cuts EU app fees to 5% in major App Store shift.

ALSO READ: Cognition CEO rejects report of SpaceX takeover bid.

READ NEXT: Microsoft Copilot flaw let hackers steal passwords with one click.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Most Popular

To Top
๐Ÿ  Home ๐Ÿ“ฐ News โšฝ Companies ๐Ÿ Startups ๐Ÿ† Markets