Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live
Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer action to take, but security teams should review sign-in logs for signs of exposure.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.