Updated
Updated · BleepingComputer · Aug 22
Microsoft Patches 5 Max-Severity Cloud Flaws in Entra ID, Azure Arc and Exchange Online
Updated
Updated · BleepingComputer · Aug 22

Microsoft Patches 5 Max-Severity Cloud Flaws in Entra ID, Azure Arc and Exchange Online

3 articles · Updated · BleepingComputer · Aug 22

Summary

  • Five maximum-severity bugs across Entra ID, Azure Arc, Exchange Online and Azure Managed Instance for Apache Cassandra have been fully patched server-side, with Microsoft saying customers need take no action.
  • CVE-2026-69836 in Entra ID let an unauthenticated attacker execute code over a network via deserialization of untrusted data in a low-complexity attack, according to Microsoft's advisory.
  • Three other flaws—CVE-2026-65816, CVE-2026-69555 and CVE-2026-65801—could let unauthenticated attackers remotely escalate privileges on Azure Arc and Exchange Online, while CVE-2026-65770 enabled remote code execution on Cassandra.
  • Microsoft said exploit code is not publicly available for the flaws and revised earlier reporting after mistakenly flagging CVE-2026-69836 as exploited in the wild.
  • The disclosures follow a September 2025 Entra ID privilege-escalation patch that researchers said could have exposed every company's tenant, underscoring recurring high-impact risks in Microsoft's cloud identity stack.

Insights

Microsoft claims no action is needed for a CVSS 10.0 Entra ID flaw, but could your cloud environment already be silently compromised?
Why did Microsoft initially claim this critical cloud identity vulnerability was actively exploited before suddenly retracting the warning?
If cloud identity breaches leave no endpoint clues, how can organizations detect unauthorized access before attackers bypass their MFA protections?