Microsoft Patches Exploited Entra ID Vulnerability

Microsoft has just rolled out a batch of 22 critical security updates to patch severe vulnerabilities in multiple products. Among these patches is one that addresses a zero-day exploit in its Entra ID service, which was being actively targeted by attackers.

The exploited vulnerability, tracked as CVE-2026-69836, had the potential for remote code execution (RCE), allowing hackers to take control of vulnerable systems. Microsoft discovered this issue internally and promptly patched it on the server side, so no action is required from customers. However, it’s worth noting that the company hasn’t shared any information about the attacks involving exploitation of this vulnerability.

Most of the other patches address critical and high-severity flaws in various Microsoft products, including Azure, Entra ID, Exchange, Fabric, and Partner Center. Some of these vulnerabilities have CVSS scores of 10/10, indicating their severity. These include elevation-of-privilege (EoP) bugs in Azure SQL Database, Azure Arc, and Exchange Online, as well as an RCE flaw in Azure Managed Instance for Apache Cassandra.

Seven other critical EoP issues were resolved, including vulnerabilities in Azure SQL Database, Microsoft Fabric, Entra ID, Azure Logic Apps, Azure Data Factory, and Azure Stack HCI. Additionally, Microsoft patched high-severity vulnerabilities in Azure Virtual Machines, Microsoft Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense.

It’s worth noting that no customer action is required for the majority of these security defects, as Microsoft has deployed the mitigations on the server side. However, this is a timely reminder to keep software up-to-date and ensure that systems are patched regularly to prevent exploitation by attackers.

This latest batch of patches comes just days after Microsoft fixed a high-severity command injection bug in Copilot that could be exploited remotely for information disclosure. The company also announced earlier this week that it was working on patches for the ShieldBreak vulnerability, which is being tracked as CVE-2026-69414 and has a CVSS score of 7.8.

In conclusion, these latest security updates are a timely reminder to stay vigilant and keep systems up-to-date. With attackers increasingly targeting zero-day exploits and actively patched vulnerabilities, it’s essential to prioritize regular patching and maintain a strong security posture.


Source: SecurityWeek — 2026-08-21