Bottom line: Security leaders must act now to patch Entra ID and prevent potential attacks.
What's happening: Microsoft patched the vulnerability on January 11, 2023, after it was reported to have been exploited in the wild by hackers targeting Entra ID users in the United States and the United Kingdom. The vulnerability, identified as CVE-2026-69836, has a CVSS score of 9.8 and is classified as Critical. The affected services include Microsoft 365, Azure, and connected services.
What to do: Security leaders should prioritize patching Entra ID and monitor their systems for signs of exploitation, using tools like Microsoft Defender Advanced Threat Protection (ATP) to detect potential attacks. Regularly review access permissions and audit logs to ensure secure access to Microsoft services.