Summary
| Parameter | Value |
|---|---|
| CVE ID (lead entry) | CVE-2026-69836 |
| Vulnerabilities covered | 13 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| Date Published | 2026-08-21 |
| Vendor | Microsoft |
| Products | Entra ID, Exchange Online, Azure SQL Database, Azure Arc, Azure Logic Apps, Azure Data Factory, Microsoft Fabric, Azure Managed Instance for Apache Cassandra |
| CVSS Score | up to 10.0 (critical) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
Microsoft disclosed 13 critical cloud service vulnerabilities in a single wave. The lead entry is CVE-2026-69836 — deserialization of untrusted data in Microsoft Entra ID, rated the maximum 10.0 CVSS, allowing an unauthenticated attacker to execute code remotely. Entra ID is the identity directory of virtually every organization running Microsoft 365, so this is a flaw in the layer that everything else depends on.
| CVE | Service | CVSS | Nature of the flaw |
|---|---|---|---|
| CVE-2026-69836 | Entra ID | 10.0 | deserialization of untrusted data → remote code execution |
| CVE-2026-65801 | Exchange Online | 10.0 | SSRF → privilege escalation |
| CVE-2026-65770 | Azure Managed Instance for Apache Cassandra | 10.0 | argument injection → code execution |
| CVE-2026-65816 | Azure Arc | 10.0 | incorrectly-resolved name or reference → privilege escalation |
| CVE-2026-69555 | Azure Arc | 10.0 | incorrect authorization → privilege escalation |
| CVE-2026-69502 | Azure SQL Database | 10.0 | SSRF → privilege escalation |
| CVE-2026-68782 | Azure SQL Database | 9.9 | SQL injection → escalation (authenticated attacker) |
| CVE-2026-68789 | Azure SQL Database | 9.9 | SQL injection → escalation (authenticated attacker) |
| CVE-2026-63509 | Microsoft Fabric | 9.9 | relative path traversal → escalation (authenticated attacker) |
| CVE-2026-69851 | Azure Active Directory | 9.9 | SSRF → escalation (authenticated attacker) |
| CVE-2026-69400 | Azure Logic Apps | 9.6 | path traversal → privilege escalation |
| CVE-2026-62834 | Azure Data Factory | 9.3 | improper verification of cryptographic signature → escalation |
| CVE-2026-66309 | Azure SQL Database | 9.1 | improper access control → escalation (authenticated attacker) |
Required Actions
The key distinction: these are not vulnerabilities you patch yourself.
Since 2024 Microsoft publishes CVEs for cloud services as part of its transparency policy, including cases where the fix has already been fully deployed service-side. For entries covering purely cloud services — Entra ID, Exchange Online, Azure SQL Database, Microsoft Fabric, Logic Apps, Data Factory — there is nothing for the customer to install.
Actions that are real on the customer side:
- Check the “Customer Action Required” field for each of these CVEs in the MSRC portal.
Where it is set to
Yes, Microsoft documents the specific step — and only those entries require operational work. - Azure Arc is the exception. Arc runs through an agent installed on your servers. Update the Connected Machine agent to the latest version on every Arc-connected machine and review role assignments in Arc-managed scopes.
- Review Entra ID audit logs and the Azure Activity Log for the period preceding the fixes — looking for unexpected privileged role grants, new application registrations and changes to service principal credentials.
- Verify permission configuration in Azure SQL Database. Three of the flaws required an authenticated attacker; the value of least-privilege application accounts persists regardless of the specific hole now being closed.
Who Is Affected?
These vulnerabilities affect organizations using Microsoft Entra ID, Exchange Online and Azure services — in practice, most mid-sized and large companies that have moved to Microsoft 365.
Azure Arc deserves the most operational attention: it is the only service listed whose component runs on customer infrastructure, and therefore the only one where skipping the update leaves a genuinely vulnerable element inside your own network.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
