Microsoft Addresses Critical Cloud Vulnerabilities in Entra ID and Azure Services

Microsoft has patched multiple maximum-severity security flaws affecting Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra. The most serious issue, tracked as CVE-2026-69836, allows unauthenticated attackers to execute remote code through deserialization of untrusted data within the identity platform. Three additional critical vulnerabilities enable unprivileged threat actors to escalate privileges remotely across Azure Arc and Exchange Online environments. A separate flaw in Azure Managed Instance for Apache Cassandra also permits remote code execution without authentication.

Microsoft confirmed that no exploit code has been observed in the wild and customers need not take any action since the fixes have already been fully deployed through backend updates. The company published these advisories to enhance transparency, following a similar critical Entra ID flaw patched in September 2025. Separately, CISA added an actively exploited Windows IKE service vulnerability to its Known Exploited Vulnerabilities catalog. The patches underscore Microsoft's commitment to automatically securing cloud infrastructure without requiring manual intervention from administrators. Organizations should continue monitoring security advisories and maintain awareness of emerging threats affecting identity and access management systems.

Read more...

Read More

Got Something To Say?

Your email address will not be published.