Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Industry update graphic for Microsoft Entra ID CVSS 10.0 vulnerability CVE-2026-69836 exploited in the wild — what it means for Australian businesses on Microsoft 365

Microsoft disclosed on Thursday that attackers exploited a maximum-severity vulnerability in Entra ID, its cloud identity platform — the service that handles every Microsoft 365 login, every Azure resource request, and every conditional access decision your business relies on.

The flaw, tracked as CVE-2026-69836, scored a perfect 10.0 on the CVSS scale. An unauthenticated attacker could execute code remotely on Microsoft’s identity infrastructure without any user interaction. No phishing email, no dodgy link — just a crafted request to a vulnerable endpoint.

Why this one’s different

Most vulnerabilities we write about here need you to do something: patch a server, update an app, change a setting. This one didn’t. Because Entra ID is a cloud-managed service, Microsoft patched it on their side before the advisory went public. Your tenant is already protected.

That’s the upside of cloud-managed identity. A comparable flaw in on-premises Active Directory would have required every organisation to download, test, and deploy a patch themselves — and based on what we see across Australian businesses, plenty would still be unpatched weeks later.

But there’s a catch

Microsoft hasn’t said who exploited it, how widely, or what the attackers did after gaining access. An attacker with code execution on the identity layer could theoretically pivot into connected workloads, hijack authentication tokens, or manipulate access policies across an entire organisation.

If your business runs on Microsoft 365, it’s worth checking your Entra ID sign-in logs for anything unusual in the past few weeks — unfamiliar service principal activity, unexpected conditional access policy changes, or new app registrations you didn’t authorise.

The broader lesson

Your identity platform is the single most valuable target in your IT environment. Every app, every file, every mailbox trusts it. When it’s compromised, everything downstream is at risk. If you’re not actively monitoring your Entra ID tenant — or you’re not sure how — talk to our team.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →