Skip to content
Tech News
← Back to articles

Microsoft patches max severity code execution, privilege escalation flaws

read original more articles
Why This Matters

Microsoft has addressed multiple critical vulnerabilities across its Entra ID, Azure Arc, and Exchange Online platforms, which could have allowed attackers to execute remote code and escalate privileges. These patches are vital for maintaining security in cloud-based identity and resource management systems, protecting both enterprise and consumer data from potential exploitation. The swift response underscores the importance of timely updates to safeguard against evolving cyber threats in the cloud ecosystem.

Key Takeaways

Microsoft has patched multiple maximum-severity vulnerabilities in its Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges.

Formerly known as Azure Active Directory (or Azure AD), it is a cloud-based IAM platform that provides Microsoft 365, Azure, or Dynamics CRM Online customers with authentication, policy enforcement, and protection across apps and resources.

The first one, discovered by Microsoft principal security engineer Robert Fitzpatrick and tracked as CVE-2026-69836, is a critical flaw in the Entra ID cloud-based IAM platform that allowed threat actors with no privileges to gain code execution in low-complexity attacks.

"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network," Microsoft said in a security advisory published on Thursday.

Yesterday, Microsoft also addressed four more maximum severity flaws, three of them allowing unauthenticated attackers to escalate privileges remotely on Azure Arc (CVE-2026-65816 and CVE-2026-69555) and Exchange Online (CVE-2026-65801).

The fourth, tracked as CVE-2026-65770, enabled remote code execution on an Azure Managed Instance for Apache Cassandra.

Microsoft says exploit code for these vulnerabilities is not yet available online and added that users don't need to take any action since the flaws have already been fully patched.

According to Microsoft, the company published the security advisories "to provide further transparency."

In September 2025, it patched another critical Entra ID privilege escalation flaw (CVE-2025-55241) reported by Outsider Security security researcher Dirk-jan Mollema that enabled attackers to gain complete access to the Microsoft Entra ID tenant of every company in the world.

On Friday, CISA also tagged a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component as actively exploited.

... continue reading