A security flaw with a CVSS score of 10.0 - the highest possible rating - resided in Microsoft Entra ID. The vulnerability, labeled CVE-2026-69836, allows unknown attackers to execute code remotely, without requiring access privileges and with no user interaction at all. The attack can even be launched over the network with low complexity.
Entra ID, a service formerly known as Azure Active Directory, is the backbone of cloud-based identity and access management for millions of organizations worldwide. In the crypto industry, the service is often used as the primary shield for institutional wallets and the gatekeeper of exchange access routes. If this flaw were leaked, hackers could take full control of systems without warning.
Patched Before Leak
Microsoft stated that it discovered and patched the flaw before publishing its CVE findings to the public. They claim there is no evidence that this vulnerability has ever been exploited in the wild. A debate arose when the exploitation status in the initial report was recorded as “Yes” and then corrected to “No,” but Microsoft described the correction as merely an informational change.
“We identified and addressed this issue, and then released CVE-2026-69836 for greater transparency. No additional customer action is required,” said a Microsoft spokesperson. The root cause of the vulnerability involves insecure deserialization - a shortcut most commonly used by attackers to inject malicious code into systems.
Bug Hunting in the AI Era
This finding highlights a new trend in the cybersecurity world, where researchers are increasingly relying on artificial intelligence to find system vulnerabilities. Last May, a researcher uncovered a flaw that had been hidden for four years in the Zcash network, using the Claude Opus 4.8 model.
Microsoft is also deploying its own weapon. The company is currently developing an AI model called MAI-Cyber-1-Flash, specifically tasked with hunting vulnerabilities. The model operates under the MDASH system, a project employing more than a hundred AI agents to scan infrastructure weaknesses.
Although the patching is complete, this disclosure is significant given Entra ID’s role in the crypto defense chain. Institutions are now aware that their primary gates were nearly breached by a maximum-score threat. Threats can emerge at any time from tier-one cloud vendors, and this time, the server guardians acted faster to close the gap before enemies could exploit it.
Reported from Decrypt.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




