{"id":"CVE-2026-69836","title":"Microsoft Entra ID Remote Code Execution Vulnerability","summary":"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C","cvssSource":"cna","cwe":["CWE-502"],"vendor":"Microsoft","product":"Microsoft Entra","affected":["entra -"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-08-21T00:00:00+00:00"},"exploitAvailable":true,"published":"2026-08-20","updated":"2026-09-16","sourceUpdated":"2026-09-16T16:22:57.988Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-69836","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836","label":"Microsoft Entra ID Remote Code Execution Vulnerability"}],"tags":["cve.org","exploit-available"],"epss":0.01555,"epssPercentile":0.7364,"exploits":{"github":2,"githubRepos":["https://github.com/sentinel-aidefense/CVE-2026-69836-EXP","https://github.com/HORKimhab/CVE-2026-69836"],"checkedAt":"2026-09-21T15:30:19.530Z"},"ingestedAt":"2026-09-08T19:08:49.670Z","slug":"CVE-2026-69836","body":"## Overview\n\nDeserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.\n\n## Affected\n\n- `entra -`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":55,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}