CVE-2026-69836
published 2026-08-20CVE-2026-69836: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
PriorityP187critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.55%
73.4th percentile
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_entra | — | — |
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Entra ID deserialization
vuldb·2026-08-21·CVSS 10.0
CVE-2026-69836 [CRITICAL] Microsoft Entra ID deserialization
A vulnerability categorized as critical has been discovered in Microsoft Entra ID. This impacts an unknown function. The manipulation results in deserialization.
This vulnerability is identified as CVE-2026-69836. The attack can be executed remotely. There is not any exploit available.
This product is a managed service. It is not possible for users to maintain vulnerability countermeasures themselves.
GHSA
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
ghsa_unreviewed·2026-08-21
CVE-2026-69836 [CRITICAL] CWE-502 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
VulnCheck
Deserialization of Untrusted Data
vulncheck·2026·CVSS 10.0
CVE-2026-69836 [CRITICAL] Deserialization of Untrusted Data
Deserialization of Untrusted Data
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Aug
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
blogs_hackernews·2026-08-24
CVE-2026-19478 ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet.
That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are.
Plenty to clean up. Here’s the short version.
## ⚡ Threat of the Week
U.S. Warns of AI-Powered Attacks on Siemens PLCs — Threat actors are using AI to write exploit scripts targeting internet-exposed Siemens S7 Series program
Hackernews
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
blogs_hackernews·2026-08-21·CVSS 10.0
CVE-2026-69836 [CRITICAL] Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Update: The story was updated after publication to note that the vulnerability has not been exploited.
Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not exploited in the wild."
"We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency . There are no additiona
2026-08-20
Published
Exploited in the wild