Microsoft has fixed a maximum-severity vulnerability in Entra ID that could have allowed an unauthorised attacker to execute code remotely through unsafe deserialization.
The vulnerability, CVE-2026-69836, scored a perfect CVSS 10.0. Microsoft fixed it on the service side, which means there is nothing for customers to patch, configure or verify. By the time the bulletin existed, the fix did too.
There was one rough edge. Microsoft's bulletin initially marked the vulnerability as having been exploited in the wild, then corrected the record and confirmed it had not been.
Why identity teams should care
A 10.0 in the identity provider is about as serious as a scoring system gets, and this one produced zero work for the teams that depend on it. That is the SaaS identity bargain in one incident: you give up the ability to patch on your own schedule, and in exchange the worst vulnerability of the month is fixed before you hear about it.
The exploitation mislabel is the part worth remembering. For a few hours, anyone triaging vendor bulletins had a maximum-severity, actively-exploited flaw in their identity provider with no action available except waiting. If your incident process has no lane for "critical, exploited, and entirely out of our hands", this was a free rehearsal for the day the label does not get corrected.
Source
Microsoft Entra ID flaw rated CVSS 10.0, The Hacker News