Redmond says the cloud identity bug is already fixed, but isnt saying who exploited it or how widely Microsoft has fixed a maximum severity vulnerability in Entra ID that attackers were already exploiting in the wild. Tracked as CVE 2026 69836, the vulnerability carries the maximum CVSS score of 10.0 and could allow an unauthenticated attacker to execute code remotely in Microsoft cloud identity service. Microsoft disclosed the flaw on Thursday , along with the unwelcome news that exploitation...

Read the full article at The Register