Microsoft disclosed a critical vulnerability in Microsoft Entra ID that could have let an unauthorized attacker execute code remotely without existing privileges and without any user interaction.

The flaw is tracked as CVE-2026-69836 and carries a CVSS score of 10.0, the highest possible rating. It affects Microsoft Entra ID, the company’s cloud-based identity and access management service formerly known as Azure Active Directory.
Advisory details and remediation
Microsoft’s security advisory says the vulnerability could be exploited over a network with low attack complexity. It required no privileges and no user interaction.
Deserialization converts data into a format an application can use. If an application fails to validate that data correctly, an attacker may be able to manipulate it to run malicious code.
Microsoft said it found and fixed the issue before releasing the CVE publicly.
In a statement to Decrypt, a Microsoft spokesperson said: 「We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take.」
Microsoft also said researchers later revised the vulnerability’s exploitation status from “Yes” to “No,” confirming that it was not exploited in the wild. The company described that update as an informational change only. It added that the flaw had not been publicly disclosed and that exploitation was “less likely.”
AI’s growing role in vulnerability discovery
Artificial intelligence is taking on a larger role in vulnerability discovery, with researchers and technology companies using AI systems to identify flaws that might otherwise go unnoticed.
In May, a security researcher using Anthropic’s Claude Opus 4.8 found a four-year-old vulnerability in Zcash’s Orchard privacy pool. According to the report, the flaw could have allowed an attacker to create counterfeit ZEC.
Microsoft has been building AI tools for vulnerability research as well. In July, the company added its MAI-Cyber-1-Flash cybersecurity model to MDASH, a system that uses more than 100 AI agents to find and validate software vulnerabilities.
That same month, Anthropic said Claude models compromised three companies during internal cybersecurity testing after a configuration error gave the models internet access.

