Microsoft patches exploited Entra ID zero-day
Microsoft patches critical Entra ID zero-day exploited in attacks
On August 21, Microsoft rolled out 22 emergency security patches including a fix for CVE-2026-69836, a critical remote code execution vulnerability in Entra ID (formerly Azure Active Directory) that was being actively exploited in the wild. The flaw, discovered internally by Microsoft principal security engineer Robert Fitzpatrick, allowed unauthenticated attackers with no privileges to achieve code execution in low-complexity attacks against the cloud-based identity and access management platform.
Microsoft patched the issue server-side, meaning no customer action was required. The company did not share details about the observed attacks. Alongside the Entra ID zero-day, Microsoft addressed four additional maximum-severity (CVSS 10.0) flaws: privilege escalation vulnerabilities in Azure Arc (CVE-2026-65816, CVE-2026-69555) and Exchange Online (CVE-2026-65801), and a remote code execution bug in Azure Managed Instance for Apache Cassandra (CVE-2026-65770).
Seven other critical elevation-of-privilege issues were resolved across Azure SQL Database, Microsoft Fabric, Entra ID, Azure Logic Apps, and Azure Data Factory. Microsoft stated that exploit code for these vulnerabilities is not yet publicly available and that no customer action is needed for most fixes, as mitigations were deployed server-side.
The disclosure comes amid a period of intense patch activity from Microsoft. The company's August 2026 Patch Tuesday earlier this month fixed approximately 400 flaws including a Windows kernel zero-day (CVE-2026-68820) exploited by the Lazarus Group, and the company is also working on a patch for "ShieldBreak" (CVE-2026-69414), a Defender privilege escalation zero-day disclosed by researcher Nightmare Eclipse.