CVE-2026-69836, deserialization RCE in Entra ID. Microsoft says it was already fixed on their side. First advisory said exploited in the wild, next day that flag was gone.
Anyone actually change anything in those 24 hours, or just watch the advisory?
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Microsoft Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Spoofing Vulnerability
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Microsoft Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Spoofing Vulnerability
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).
Azure Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Elevation of Privilege Vulnerability
Azure Entra ID Elevation of Privilege Vulnerability