CVE-2026-62869
Azure Entra ID Spoofing Vulnerability
Description
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-62869 is a Microsoft Entra ID weakness where a remotely authenticated attacker may be able to impersonate other identities. This is serious enough for most small businesses to act quickly—especially if your Entra ID is exposed to untrusted logins or you have accounts or integrations that could be abused.
CVE-2026-62869 is an Azure/Microsoft Entra ID spoofing issue caused by insufficient verification of identity/source authenticity; a remote attacker with low-level authentication can convince Entra ID that data is genuine even when it was tampered with, enabling full compromise of confidentiality, integrity, and availability.
What to do now
- Check whether you run Microsoft Entra ID (or rely on Microsoft Entra ID features like login, SSO, or access control).
- Review your most recent Entra ID/Microsoft identity updates and confirm you have applied the fix from the MSRC guidance for CVE-2026-62869.
- If you cannot confirm the update status, contact your Microsoft/IT support channel and ask specifically whether CVE-2026-62869 has been remediated for your Entra ID configuration.
- Identify and reduce exposure of any accounts, service principals, API permissions, or integrations that could provide “low-level” authentication to Entra ID, and rotate secrets/credentials where needed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62869 and every CVE in our database. Create a free account — no credit card required.
Create Free Account