Microsoft publishes a CVSS 10.0 Entra ID deserialization flaw as already mitigated
- Sources: MSRC CVE-2026-69836
- Summary: CVE-2026-69836 is a deserialization flaw in Entra ID scored 10.0. Microsoft states the fix is deployed service-side and that customers have no action to take.
- Why it matters: The score is maximum but the fix is already deployed, which is the pattern to expect from Microsoft cloud CVEs published for transparency rather than for customer action.