Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks.

Microsoft says CVE-2026-69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no user action required.

Redmond says the cloud identity bug is already fixed, but isn't saying who exploited it or how widely