Vulnerability threat dossier

CVE-2026-69836

microsoftentra id

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

VTP deterministic threat24.3of 100 · CVSS excluded

VTP analyst assessment

Critical Microsoft Entra ID deserialization RCE

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence88%
Public exploitation · VTP factCONFIRMED

Assessment

Untrusted-data deserialization in Microsoft Entra ID permits unauthenticated network code execution with CVSS 10.0 impact. The bundle records historical CISA KEV exploitation reporting, but the CVE is absent from the current catalog and a later CERT update says Microsoft clarified that it was not actively exploited; this conflict remains material.

Why it matters

  • The stated attack requires no privileges or user interaction and can fully affect confidentiality, integrity, and availability.
  • Historical KEV status establishes that exploitation was reported globally at one point, even though it does not establish VTP observation.

Evidence

4 record references and 4 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The reason for KEV withdrawal and the precise relationship between historical reporting and Microsoft's later clarification are not supplied.

Press reports have unknown independence, no exploit is identified, and first-party observation is unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Further CISA or Microsoft clarification of exploitation status and the KEV withdrawal.

AI baseline history (3)
  1. BASELINE ASSESSED
    Critical Microsoft Entra ID deserialization RCEgpt-5.6-sol · high
  2. BASELINE ASSESSED
    Possible linkage to exploited Entra ID flawgpt-5.6-sol · high
  3. BASELINE ASSESSED
    Reported exploited Microsoft Entra ID flaw with weak attributiongpt-5.6-sol · high
Technical severityCRITICALCVSS 10.0 · technical context
Public exploitationCONFIRMEDGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.0274th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA previously listed this vulnerability in KEV. It is not in the current catalog; withdrawal does not negate the historical exploitation report.

  2. 02

    EPSS is 0.02; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV WITHDRAWNCISA KEV entry withdrawn
CERT ADVISORYNew CERT advisory
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

1 primary sources · 0 dependent secondary reports · 4 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 15:3031 Aug
    KEV WITHDRAWN

    CISA KEV entry withdrawn

    The CVE is no longer present in the current CISA KEV catalog. VTP retained the historical record; withdrawal does not by itself negate earlier exploitation reporting.

  2. 00:0021 Aug
    CERT ADVISORY

    New CERT advisory

    CERT-FR published evidence linked to CVE-2026-69836.

  3. 00:0021 Aug
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

CVE-2021-27101CVE-2023-34362CVE-2026-12143CVE-2026-13242CVE-2026-14682CVE-2026-15580CVE-2026-15748CVE-2026-15826CVE-2026-18051CVE-2026-18963CVE-2026-19478CVE-2026-19505CVE-2026-19506CVE-2026-19507CVE-2026-19508CVE-2026-19509CVE-2026-20030CVE-2026-20231CVE-2026-20315CVE-2026-20317CVE-2026-20318CVE-2026-20319CVE-2026-20357CVE-2026-20358CVE-2026-20359CVE-2026-24301CVE-2026-25895CVE-2026-32475CVE-2026-40144CVE-2026-40145CVE-2026-41472CVE-2026-41473CVE-2026-47836CVE-2026-47841CVE-2026-55803CVE-2026-57580CVE-2026-59270CVE-2026-63093CVE-2026-63182CVE-2026-64849CVE-2026-65346CVE-2026-65770CVE-2026-65801CVE-2026-65816CVE-2026-65922CVE-2026-66794CVE-2026-6837CVE-2026-69106CVE-2026-69502CVE-2026-69555CVE-2026-69836CVE-2026-73570CVE-2026-74934CVE-2026-74935CVE-2026-74936CVE-2026-74949CVE-2026-75501CVE-2026-75874CVE-2026-76017CVE-2026-76034CVE-2026-76036CVE-2026-76310CVE-2026-76311CVE-2026-76312CVE-2026-76389CVE-2026-76395CVE-2026-76404
Separate evidence group
Original

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

CVE-2025-55241CVE-2026-65770CVE-2026-65801CVE-2026-65816CVE-2026-69555CVE-2026-69836
Separate evidence group
Original

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek .

CVE-2026-24301CVE-2026-62834CVE-2026-63509CVE-2026-65770CVE-2026-65801CVE-2026-65816CVE-2026-66309CVE-2026-68782CVE-2026-68789CVE-2026-69400CVE-2026-69414CVE-2026-69502CVE-2026-69555CVE-2026-69836CVE-2026-69851
Separate evidence group
Original

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

CVE-2026-68820CVE-2026-69836
Separate evidence group
Original

Vulnérabilité dans Microsoft Entra ID (21 août 2026)

**[Mise à jour du 24 août 2026]** Microsoft a modifié son bulletin de sécurité pour préciser que la vulnérabilité CVE-2026-69836 n'est pas activement exploitée. **[Publication initiale]** Une vulnérabilité a été découverte dans Microsoft Entra ID. Elle permet à un attaquant de provoquer une...

CVE-2026-69836
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score24.3vtp-threat-v1-public
Public exploitation24 / 30
EPSS prediction0.31 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
10 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-502
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.