Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity and access management service and stems from deserialization of untrusted data that can let an attacker execute code over a network. Microsoft says the issue has already been fully mitigated, so no customer action is required.
Related Happenings
PaperCut customer confirmed compromise incidents
Incident
H score41
First: 27.08.2026 19:31
Last: 27.08.2026 19:31
Sources 1
About this happening:
PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
PaperCut customer confirmed compromise incidents
IncidentAbout this happening: PaperCut NG and PaperCut MF are under active zero-day exploitation, with confirmed customer incidents affecting all versions of the print management software....
Latest development: 01.09.2026 10:48
Attackers are abusing CVE-2026-81578 and CVE-2026-82078 against PaperCut NG/MF print management servers to hijack the external user-lookup function and dump DB tables via Derby, with Defused observing exploit activity in honeypots since late yesterday UTC (Aug 29th).
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/Mitigation
H score31
First: 10.08.2026 15:25
Last: 10.08.2026 15:25
Sources 1
About this happening:
Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Windows passkey relay mitigation for CVE-2026-34348
Advisory/MitigationAbout this happening: Microsoft's CVE-2026-34348 mitigation for Windows Event Logging Service and the reported passkey relay assertions issue reduces exposure to replay-style authentication...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
Vulnerability
H score32
First: 17.06.2026 11:32
Last: 17.06.2026 11:32
Sources 1
About this happening:
Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
Microsoft Malware Protection Engine race-condition elevation-of-privilege remote code execution flaw (CVE-2026-50656)
VulnerabilityAbout this happening: Microsoft has released a security update for CVE-2026-50656 after public disclosure of RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protecti...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector Action
H score48
First: 01.06.2026 15:30
Last: 01.06.2026 15:30
Sources 1
About this happening:
Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
CCB urgent patch warning for CVE-2026-41089 on Windows servers
Public Sector ActionAbout this happening: Belgium's CCB warned that CVE-2026-41089 is being actively exploited in the wild, urging admins to immediately patch vulnerable Windows servers because the fla...
Microsoft My Sign-Ins MFA outage
Service Disruption
H score25
First: 01.06.2026 14:40
Last: 01.06.2026 14:40
Sources 1
About this happening:
Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Microsoft My Sign-Ins MFA outage
Service DisruptionAbout this happening: Microsoft is dealing with an ongoing outage that is blocking some users from setting up multi-factor authentication (MFA) and accessing My Sign-Ins. Affected users...
Timeline
-
21.08.2026 09:06 3 articles · 13d ago
Microsoft warns of CVE-2026-69836 in Entra ID
Initial DisclosureMicrosoft warned that CVE-2026-69836 in Microsoft Entra ID, previously Azure Active Directory or Azure AD, is a maximum-severity remote code execution flaw caused by deserialization of untrusted data. Microsoft said the flaw had been exploited in the wild, that it was already fully mitigated, and that no customer action is required.
Show sources
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution — thehackernews.com — 21.08.2026 09:06
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution — thehackernews.com — 21.08.2026 09:06
- Microsoft warns of max severity Entra ID flaw exploited in attacks — www.bleepingcomputer.com — 21.08.2026 14:04