Microsoft disclosed on Thursday that attackers exploited a maximum-severity vulnerability in Entra ID, its cloud identity platform — the service that handles every Microsoft 365 login, every Azure resource request, and every conditional access decision your business relies on.
The flaw, tracked as CVE-2026-69836, scored a perfect 10.0 on the CVSS scale. An unauthenticated attacker could execute code remotely on Microsoft’s identity infrastructure without any user interaction. No phishing email, no dodgy link — just a crafted request to a vulnerable endpoint.
Why this one’s different
Most vulnerabilities we write about here need you to do something: patch a server, update an app, change a setting. This one didn’t. Because Entra ID is a cloud-managed service, Microsoft patched it on their side before the advisory went public. Your tenant is already protected.
That’s the upside of cloud-managed identity. A comparable flaw in on-premises Active Directory would have required every organisation to download, test, and deploy a patch themselves — and based on what we see across Australian businesses, plenty would still be unpatched weeks later.
But there’s a catch
Microsoft hasn’t said who exploited it, how widely, or what the attackers did after gaining access. An attacker with code execution on the identity layer could theoretically pivot into connected workloads, hijack authentication tokens, or manipulate access policies across an entire organisation.
If your business runs on Microsoft 365, it’s worth checking your Entra ID sign-in logs for anything unusual in the past few weeks — unfamiliar service principal activity, unexpected conditional access policy changes, or new app registrations you didn’t authorise.
The broader lesson
Your identity platform is the single most valuable target in your IT environment. Every app, every file, every mailbox trusts it. When it’s compromised, everything downstream is at risk. If you’re not actively monitoring your Entra ID tenant — or you’re not sure how — talk to our team.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
