CVE-2026-69836: Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
— CISA
Microsoft Entra ID Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
No. The vulnerability is described as exploitable by an unauthorized attacker over a network, with no privileges or user interaction required.
What is the potential impact of successful exploitation?
Successful exploitation can allow remote code execution. The supplied severity metrics indicate high impact to confidentiality, integrity, and availability, with scope changed.
Has this vulnerability been exploited in the wild?
Yes. It is flagged as exploited and is listed in the Known Exploited Vulnerabilities catalog as of 2026-08-20.