Circuit Wire — a daily news update from the Circuit.
Microsoft published an advisory on Thursday for a flaw in Entra ID that carried the maximum CVSS score of 10.0 and was labelled as exploited in the wild. On Saturday the company said it had flagged the bug as exploited by mistake.
The flaw is tracked as CVE-2026-69836 and sits in the cloud identity platform formerly known as Azure Active Directory. Microsoft's advisory describes it as deserialization of untrusted data that lets an unauthorized attacker execute code over a network. The CVSS metrics show a remotely reachable bug with low attack complexity that needs no privileges and no user interaction. Microsoft credited principal security engineer Robert Fitzpatrick with finding and reporting it.
Entra ID handles authentication and access for Microsoft 365, Azure and Dynamics CRM Online customers, so it governs entry to cloud applications and corporate resources. Because it is a service Microsoft runs, the company repaired its own infrastructure rather than shipping a patch. It said the vulnerability was already fully mitigated and that customers need take no action.
Microsoft addressed four more maximum-severity cloud flaws the same week. Three let unauthenticated attackers escalate privileges remotely: two in Azure Arc, tracked as CVE-2026-65816 and CVE-2026-69555, and one in Exchange Online, tracked as CVE-2026-65801. The fourth, CVE-2026-65770, allowed remote code execution on an Azure Managed Instance for Apache Cassandra. Microsoft said exploit code for the set is not yet publicly available, and that it published the advisories "to provide further transparency."
Coverage on Friday noted how little Microsoft had said about the reported attacks. The company did not identify who was exploiting the flaw, when the activity began, how widespread it was, or what attackers did afterwards. No public technical details of an attack chain existed. Microsoft then withdrew the exploitation label the following day.
Entra ID has drawn scrutiny before. In September 2025 Microsoft patched CVE-2025-55241, a privilege escalation flaw reported by Dirk-jan Mollema of Outsider Security, which could have given an attacker complete access to the Entra ID tenant of every company in the world. Separately, CISA tagged a critical remote code execution flaw in the Windows Internet Key Exchange Service Extensions component as actively exploited on Friday.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

