Microsoft Patches Maximum-Severity Code Execution and Privilege Escalation Flaws
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges. Formerly known as Azure Active Directory (or Azure AD), Entra ID is a cloud-based identity and access management (IAM) platform that provides Microsoft 365, Azure, and Dynamics CRM Online customers with authentication, policy enforcement, and protection across applications and resources.
The first vulnerability, discovered by Microsoft principal security engineer Robert Fitzpatrick and tracked as CVE-2026-69836, is a critical flaw in the Entra ID cloud-based IAM platform that allowed threat actors with no privileges to gain code execution in low-complexity attacks. “Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network,” Microsoft stated in a security advisory published on Thursday. Yesterday, Microsoft also addressed four more maximum-severity flaws, three of which allow unauthenticated attackers to remotely escalate privileges on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801).
Details of Patched Flaws and Security Context
The fourth flaw, tracked as CVE-2026-65770, enabled remote code execution on an Azure Managed Instance for Apache Cassandra. Microsoft stated that exploit code for these vulnerabilities is not yet available online, adding that users do not need to take any action since the flaws have already been fully patched. According to Microsoft, the company published the security advisories “to provide further transparency.”
In September 2025, Microsoft patched another critical Entra ID privilege escalation flaw (CVE-2025-55241) reported by Outsider Security researcher Dirk-jan Mollema that enabled attackers to gain complete access to the Microsoft Entra ID tenant of every company worldwide. On Friday, CISA also tagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited. Following a statement from Microsoft clarifying that it had mistakenly flagged CVE-2026-69836 as exploited in the wild, the story was revised.
Once attackers have valid credentials, only 37% of their actions are blocked. Overall prevention scores can hide what happens after initial access. When attackers use valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Source: Original Article




