Skip to content
Security Alerts

CVE-2026-69836 and 12 more: Microsoft's August cloud bulletin (Entra ID, Azure, Exchange Online)

Microsoft disclosed 13 critical vulnerabilities in cloud services - Entra ID, Exchange Online, Azure SQL Database, Azure Arc, Logic Apps, Data Factory and Fabric. Find out which ones need action from you...

Summary

ParameterValue
CVE ID (lead entry)CVE-2026-69836
Vulnerabilities covered13
Alert SourceGitHub Advisory - Critical Vulnerability
Date Published2026-08-21
VendorMicrosoft
ProductsEntra ID, Exchange Online, Azure SQL Database, Azure Arc, Azure Logic Apps, Azure Data Factory, Microsoft Fabric, Azure Managed Instance for Apache Cassandra
CVSS Scoreup to 10.0 (critical)
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Microsoft disclosed 13 critical cloud service vulnerabilities in a single wave. The lead entry is CVE-2026-69836 — deserialization of untrusted data in Microsoft Entra ID, rated the maximum 10.0 CVSS, allowing an unauthenticated attacker to execute code remotely. Entra ID is the identity directory of virtually every organization running Microsoft 365, so this is a flaw in the layer that everything else depends on.

CVEServiceCVSSNature of the flaw
CVE-2026-69836Entra ID10.0deserialization of untrusted data → remote code execution
CVE-2026-65801Exchange Online10.0SSRF → privilege escalation
CVE-2026-65770Azure Managed Instance for Apache Cassandra10.0argument injection → code execution
CVE-2026-65816Azure Arc10.0incorrectly-resolved name or reference → privilege escalation
CVE-2026-69555Azure Arc10.0incorrect authorization → privilege escalation
CVE-2026-69502Azure SQL Database10.0SSRF → privilege escalation
CVE-2026-68782Azure SQL Database9.9SQL injection → escalation (authenticated attacker)
CVE-2026-68789Azure SQL Database9.9SQL injection → escalation (authenticated attacker)
CVE-2026-63509Microsoft Fabric9.9relative path traversal → escalation (authenticated attacker)
CVE-2026-69851Azure Active Directory9.9SSRF → escalation (authenticated attacker)
CVE-2026-69400Azure Logic Apps9.6path traversal → privilege escalation
CVE-2026-62834Azure Data Factory9.3improper verification of cryptographic signature → escalation
CVE-2026-66309Azure SQL Database9.1improper access control → escalation (authenticated attacker)

Required Actions

The key distinction: these are not vulnerabilities you patch yourself.

Since 2024 Microsoft publishes CVEs for cloud services as part of its transparency policy, including cases where the fix has already been fully deployed service-side. For entries covering purely cloud services — Entra ID, Exchange Online, Azure SQL Database, Microsoft Fabric, Logic Apps, Data Factory — there is nothing for the customer to install.

Actions that are real on the customer side:

  1. Check the “Customer Action Required” field for each of these CVEs in the MSRC portal. Where it is set to Yes, Microsoft documents the specific step — and only those entries require operational work.
  2. Azure Arc is the exception. Arc runs through an agent installed on your servers. Update the Connected Machine agent to the latest version on every Arc-connected machine and review role assignments in Arc-managed scopes.
  3. Review Entra ID audit logs and the Azure Activity Log for the period preceding the fixes — looking for unexpected privileged role grants, new application registrations and changes to service principal credentials.
  4. Verify permission configuration in Azure SQL Database. Three of the flaws required an authenticated attacker; the value of least-privilege application accounts persists regardless of the specific hole now being closed.

Who Is Affected?

These vulnerabilities affect organizations using Microsoft Entra ID, Exchange Online and Azure services — in practice, most mid-sized and large companies that have moved to Microsoft 365.

Azure Arc deserves the most operational attention: it is the only service listed whose component runs on customer infrastructure, and therefore the only one where skipping the update leaves a genuinely vulnerable element inside your own network.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist