// Alert

Microsoft Azure threat report

Microsoft Entra ID (cloud identity and access management service in Azure) suffered a critical remote code execution vulnerability (CVE-2026-69836) caused by improper deserialization of untrusted data. The vulnerability was actively exploited in the wild before disclosure on August 20, 2026, and required no authentication. Microsoft has already deployed the fix server-side, but organizations should review identity logs and conditional access policies for signs of compromise.

// Get alerts for Microsoft Azure