InfoSec News Nuggets – 08/26/2026
Brief
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Microsoft disclosed a maximum-severity flaw in its Entra ID identity service, tracked as CVE-2026-69836 with a CVSS score of 10. 0, tracing back to unsafe deserialization of untrusted data that could let an attacker execute code remotely.
Initial guidance said the bug had already been exploited in the wild, but after follow-up questions the company revised its assessment to confirm no exploitation had actually occurred and that the issue was fully mitigated on the server side, with no action required from customers.
The engineer who reported the flaw was credited internally, and the disclosure adds to a run of high-severity fixes this month, including a separate Windows zero-day used by the Lazarus Group.
