Microsoft патчит уязвимость в Entra ID, набравшую 10 баллов по шкале CVSS
Microsoft has resolved five critical vulnerabilities across its cloud infrastructure, including a severe defect in Entra ID assigned the identifier CVE-2026-69836. Discovered internally by Robert Fitzpatrick, this flaw allows unauthorized remote code execution via insecure deserialization of untrusted data without requiring authentication or user interaction, earning it a maximum CVSS score of 10.0. While the initial advisory suggested active exploitation, Microsoft later clarified that the bug was not used in the wild and has been fully mitigated on the service side, so customers do not need to apply manual patches.
The update also addresses privilege escalation issues in Azure Arc (CVE-2026-65816, CVE-2026-69555) and Exchange Online (CVE-2026-65801), along with a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra (CVE-2026-65770).