CVE-2026-69836: Inside the CVSS 10.0 Entra ID Deserialization RCE
Microsoft disclosed a maximum-severity remote code execution flaw in Entra ID caused by unsafe deserialization. No patch is needed on your end, but the incident is a hard reminder to instrument identity logging before the next one isn't silently fixed for you.