Aug 222026 Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution Microsoft says CVE-2026–69836, a CVSS 10.0 Entra ID RCE flaw, has been exploited in the wild but is fully mitigated with no user action required.