Microsoft patches Exploited Entra ID vulnerability

Microsoft on Thursday announced the release of 22 new security updates that resolve serious vulnerabilities in multiple products, including a critical Entra ID zero-day used in attacks.

The Entra ID flaw used is tracked as CVE-2026-69836and may have been used for remote code execution (RCE). Microsoft discovered the problem internally and fixed it on the server side without requiring any action from customers.

The tech giant has not shared any information about the attacks involving the CVE-2026-69836 exploit.

Most of the other stickers addressing critical and critical gaps in Microsoft Azure, Entra ID, Exchange, Fabric and Partner Center products.

The most serious of these include elevation of privilege (EoP) vulnerabilities in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555 and CVE-2026-65816), and Exchange Online (CVE-2026-65801), as well as an RCE flaw in Azure Managed Instance for Apache Cassandra (CVE-2026-65770), all with a CVSS result. 10/10.

Seven other critical EoP issues were resolved: CVE-2026-68782 (Azure SQL Database), CVE-2026-63509 (Microsoft Fabric), CVE-2026-69851 (Entra ID), CVE-2026-68789 (Azure SQL Database), CVE-2026-69400 (Azure Logic Apps), CVE-2026-62834 (Azure Data Factor) and CVE-2026-66309 (Azure SQL Database).

Advertising. Scroll to continue reading.

Additionally, Microsoft patched high-severity vulnerabilities in Azure Virtual Machines, Microsoft Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense.

Most of these security flaws do not require client-side action because Microsoft has implemented server-side mitigations.

Earlier this week, Microsoft fixed a high-severity command injection bug in Copilot that could be used remotely for information disclosure (CVE-2026-24301).

Last week, the company announced that it was working on patches for ShieldBreak, a Defender zero-day exploit dropped on August 2026 Patch Tuesday by security researcher Nightmare Eclipse (aka Chaotic Eclipse).

The company estimates that the vulnerability that ShieldBreak targets is a high-severity bug that is now being tracked as CVE-2026-69414 (CVSS score of 7.8).

“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as ‘ShieldBreak’. We are working to provide a high-quality security update that addresses this vulnerability,” the company said.

Related: CISA urges immediate remediation of exploited TrueConf vulnerabilities

Related: An exploit is expected for a critical authentication bypass fixed in Citrix NetScaler

Related: Critical GitLab flaw exploited shortly after disclosure

Related: CISA demands immediate patching of Microsoft, VMware, Apple exploited vulnerabilities

Leave a Reply

Your email address will not be published. Required fields are marked *