Microsoft Patches 5 Max-Severity Cloud Flaws in Entra ID, Azure Arc and Exchange Online
Updated
Updated · BleepingComputer · Aug 22
Microsoft Patches 5 Max-Severity Cloud Flaws in Entra ID, Azure Arc and Exchange Online
3 articles · Updated · BleepingComputer · Aug 22
Summary
Five maximum-severity bugs across Entra ID, Azure Arc, Exchange Online and Azure Managed Instance for Apache Cassandra have been fully patched server-side, with Microsoft saying customers need take no action.
CVE-2026-69836 in Entra ID let an unauthenticated attacker execute code over a network via deserialization of untrusted data in a low-complexity attack, according to Microsoft's advisory.
Three other flaws—CVE-2026-65816, CVE-2026-69555 and CVE-2026-65801—could let unauthenticated attackers remotely escalate privileges on Azure Arc and Exchange Online, while CVE-2026-65770 enabled remote code execution on Cassandra.
Microsoft said exploit code is not publicly available for the flaws and revised earlier reporting after mistakenly flagging CVE-2026-69836 as exploited in the wild.
The disclosures follow a September 2025 Entra ID privilege-escalation patch that researchers said could have exposed every company's tenant, underscoring recurring high-impact risks in Microsoft's cloud identity stack.