Microsoft fixes maximum severity code execution errors and privilege escalation errors

Microsoft fixes maximum severity code execution errors and privilege escalation errors

Microsoft

Microsoft has fixed multiple maximum severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to remotely execute code and escalate privileges.

Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across all apps and resources.

The first was discovered and tracked by Microsoft’s senior security engineer, Robert Fitzpatrick CVE-2026-69836is a critical flaw in the cloud-based IAM platform Entra ID that allowed unprivileged threat actors to execute code in low-complexity attacks.

Picture

“Deserializing untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.” Microsoft said in a security advisory released Thursday.

Yesterday, Microsoft also fixed four additional maximum severity bugs, three of which allow unauthenticated attackers to remotely escalate privileges on Azure Arc (CVE-2026-65816 And CVE-2026-69555) and Exchange Online (CVE-2026-65801).

The fourth, pursued as CVE-2026-65770Enabled remote code execution on an Azure Managed Instance for Apache Cassandra.

Microsoft says that the exploit code for these vulnerabilities is not yet available online, adding that users do not need to take any action as the vulnerabilities are already fully fixed.

According to Microsoft, the company published the security advisories “to provide greater transparency.”

In September 2025, another critical Entra ID privilege escalation bug was fixed (CVE-2025-55241), reported by Outsider Security security researcher Dirk-jan Mollema, enabled attackers to gain full access to the Microsoft Entra ID tenant of any company in the world.

On Friday, CISA also marked a critical Remote Code Execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.

Update August 22, 2:56 a.m. EDT: Revised story and title following a statement from Microsoft that CVE-2026-69836 was incorrectly flagged as being exploited in the wild. The original story can be found here.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *