Microsoft Corporation has completed the process of fixing a critical vulnerability in its cloud-based identity and access management service, Entra ID. The issue in question is a flaw identified as CVE-2026-69836, which received the highest possible score on the CVSS scale — 10.0. This is an extremely rare case where a vulnerability is recognized as absolutely critical in terms of potential damage.

The essence of the problem is that the flaw allowed an unauthorized remote attacker to execute arbitrary code on the system without any action on the part of the victim. In other words, exploitation required neither clicks on links nor opening malicious files — the attack could be fully automated and launched remotely. This vector makes the vulnerability especially dangerous for enterprise environments, where Entra ID is used as a central access control element for thousands of applications and resources.

It is important to emphasize that the nature of the vulnerability points to issues in the logic of processing authentication requests or in components responsible for token validation. Given that Entra ID is the foundation of the hybrid and cloud infrastructure of many organizations, a potential compromise of this system would mean the complete compromise of all associated services — from email to corporate databases.

Microsoft has already released updates closing this flaw, but the technical implementation details have not yet been fully disclosed. I recommend that all administrators using Entra ID immediately check audit logs for suspicious activity over the past few weeks and ensure that all automatic updates have been applied.

My comment: A CVSS score of 10.0 is not just a formality. It is a signal that the vulnerability could have been exploited as a "zero-day" before the patch was released. For the cryptocurrency market and DeFi projects, where access to wallets and exchanges is often tied to corporate SSO solutions, such incidents are a direct reminder of the need to diversify access keys and implement hardware tokens. Do not rely solely on a cloud provider, even if it is Microsoft.