CuraSec

Act active

Microsoft Entra ID CVSS 10.0 RCE Flaw Exploited in the Wild

2026-08-21 11:38 UTC · The Hacker News · read the source ↗ #entra-id#rce#active-exploitation
  • Engineer — Act: Microsoft has applied a server-side fix requiring no customer patch, but active exploitation occurred before remediation — audit Entra ID sign-in and audit logs for anomalous authentication, new service principals, or privilege escalation events from the period prior to the fix, and verify no credential or token abuse persists.
  • SOC/IR — Act: Confirmed in-the-wild exploitation of an identity provider with a public PoC warrants an immediate hunt — query Entra ID audit and sign-in logs for suspicious app registrations, delegated permission grants, and admin role assignments occurring in the exploitation window, and tune detections for anomalous OAuth consent flows.
  • Leader — Act: A CVSS 10.0 actively exploited RCE on the organization’s cloud identity plane is a board-level event analogous to Log4Shell in blast radius — brief leadership this week on the pre-patch exposure window and confirm with the security team that no evidence of compromise was found in Entra ID logs before Microsoft’s server-side fix landed.
  • Signals: CVE-2026-69836 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.