INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Microsoft Entra ID Flaw Exploited in Wild Allows Remote Code Execution

| 2026-08-21 11:04 CRITICAL HIGH
Executive Summary AI-generated
The Microsoft Entra ID vulnerability, tracked as CVE-2026-69836 and later patched in August 2026, is a critical security flaw that allowed threat actors to gain code execution in low-complexity attacks. This exploit was discovered by Microsoft principal security engineer Robert Fitzpatrick and identified as a maximum-severity vulnerability with a CVSS score of 7.0. The company addressed four more high-severity flaws, including CVE-2026-65816 and CVE-2026-69555, which enabled unauthenticated attackers to escalate privileges remotely on Azure Arc and Exchange Online. Additionally, the Windows Internet Key Exchange (IKE) Service Extensions component was tagged as actively exploited due to a critical-severity remote code execution flaw. Microsoft warns of max severity Entra ID vulnerability exploited in attacks, prompting users to take no action since the flaw has already been fully patched.
Technical Mitigations AI-generated
* Implement secure coding practices and input validation to prevent deserialization of untrusted data, which can lead to remote code execution. * Regularly update and patch Entra ID and other Microsoft services to ensure that known vulnerabilities are addressed before they can be exploited. * Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and block potential attacks on the Entra ID platform. * Monitor network traffic and logs for suspicious activity, which may indicate an attempt to exploit the CVE-2026-69836 vulnerability.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Dream JobOperation Dream JobOperation DreamJobOperation DreamJob Lazarus GroupLazarus Group CVE-2026-68820CVE-2026-68820 CVE-2026-65770CVE-2026-65770 CVE-2026-69555CVE-2026-69555 CVE-2025-60719CVE-2025-60719 CVE-2026-62815CVE-2026-62815 CVE-2026-72971CVE-2026-72971 CVE-2026-65816CVE-2026-65816 CVE-2025-49113CVE-2025-49113 CVE-2026-62911CVE-2026-62911 CVE-2026-59124CVE-2026-59124 CVE-2026-62832CVE-2026-62832 CVE-2025-55241CVE-2025-55241 CVE-2026-55040CVE-2026-55040 CVE-2026-69836CVE-2026-69836 CVE-2026-65801CVE-2026-65801 CVE-2026-62893CVE-2026-62893 CVE-2026-62878CVE-2026-62878 CVE-2026-63520CVE-2026-63520 CVE-2024-38193CVE-2024-38193
Target & Sectors
DPRK DPRK FIVE_EYES FIVE_EYES DACH DACH LATAM LATAM governmentgovernment aviationaviation aerospaceaerospace mediamedia defensedefense technologytechnology
Incident Timeline
‎around 2021
Threat actors exploited a vulnerability in Microsoft Entra ID, using FudModule to execute remote code on targeted systems.
tactic Privilege Escalation
‎2025/08/11
Threat actors exploited a Microsoft Entra ID flaw in Wild Remote Code Execution by using the ESET report to publish a sample containing a PDB path that led to exploitation of Troy backdoor.
organisation ESET
organisation E:\Work\Troy\안정화\
organisation Command and Control
‎2025/08/12
Threat actors exploited a recently discovered flaw in Microsoft's Entera ID system, allowing them to execute arbitrary code remotely.
‎September 2025
Threat actors exploited a previously unknown vulnerability in Microsoft Entra ID, allowing them to gain complete access to the tenant of every company worldwide.
tactic Privilege Escalation
vulnerability CVE-2025-55241
organisation Outsider Security
organisation Dirk
‎November 2025
Threat actors exploited a previously unknown vulnerability in Microsoft Entra ID, which they used to target the AFD.sys driver.
vulnerability CVE-2025-60719
‎May 18
Threat actors exploited a vulnerability in Microsoft Entra ID to gain unauthorized access via remote code execution.
‎July 7, 2026
Threat actors exploited a Microsoft Entra ID flaw in the Afd4Eop12_x64.dll file.
vulnerability CVE-2026-68820
observable Afd4Eop12_x64.dll
organisation UTC
‎2026/07/13
Threat actors exploited a Microsoft Entra ID flaw in Wild Remote Code Execution.
organisation LegacyHive
organisation Nightmare
‎July 2026
Threat actors used a previously documented exploit of the Microsoft Entra ID flaw to target an infected system via in infection chain 2: Trojanized PDF viewer.
campaign Operation Dream Job
general_metric 2.0 reference
‎at least early July 2026
Threat actors used a previously undocumented vulnerability in Microsoft Entra ID to exploit a remote code execution on Windows 11 systems.
infrastructure Windows
general_metric 11 Windows
organisation Operation ‘Dream Job
‎Jul 28, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎July 28
Threat actors exploited a Microsoft Entra ID flaw to target Check Point Research.
organisation Microsoft
organisation Check Point Research
‎Jul 31, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎Aug 5, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎Aug 11, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎August 11, 2026
Threat actors exploited the Microsoft Entra ID Flaw to target vulnerable systems.
vulnerability CVE-2026-68820
‎August 11
Threat actors exploited the Microsoft Entra ID Flaw in conjunction with AFD.sys, a kernel driver underlying Windows Sockets.
tactic Privilege Escalation
infrastructure Windows
vulnerability CVE-2026-68820
organisation Microsoft
organisation Check Point Research
‎Aug 12, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎2026/08/20
Threat actors exploited a Microsoft Entra ID flaw to target Azure Arc devices, including Exchange Online.
vulnerability CVE-2026-65816
vulnerability CVE-2026-69555
vulnerability CVE-2026-65801
‎Aug 21, 2026
Microsoft's Entra ID authentication system suffered a flaw allowing threat actors to execute arbitrary code remotely.
‎2026/08/21
Microsoft fixed the vulnerability.
infrastructure Windows
organisation Windows Ancillary Function
organisation CVSS
threat_actor Lazarus Group
organisation FudModule
organisation LPE
organisation ML-KEM
organisation EDR
organisation Microsoft 365
organisation Azure Active Directory
organisation Dynamics CRM Online
organisation BleepingComputer
organisation an Azure Managed Instance for Apache Cassandra
organisation Microsoft
infrastructure Roundcube
organisation CVE-2025
organisation PHP Object Deserialization
organisation Lockheed
infrastructure 3.1
organisation FudModule 3.1
organisation North Korean
organisation Troy
organisation CVE-2026-68820
organisation Check Point
organisation ETW
organisation CVE-2026
organisation Vulnerability / Cyber Espionage
organisation Microsoft Windows
organisation FudModule 3.1
organisation Winsock
organisation Windows Deployment Services
organisation TFTP
organisation WDS
organisation PXE
organisation Windows User Profile Service
organisation the Container Isolation FS Filter
organisation the User Profile Service
organisation the Windows Ancillary Function
organisation CVE-2026-62832
organisation the Windows User Profile Service
organisation Windows Container Isolation FS
organisation Microsoft Patches
organisation Vulnerability / Windows Security
organisation Put CVE-2026-68820
organisation PvPlugin
organisation the Windows Ancillary Function Driver
organisation Entra ID
organisation Entra
organisation IAM
organisation CVE
organisation The Blue Report 2026
organisation Automox
organisation Reconnaissance General Bureau
organisation Check Point Research
infrastructure 7.0
organisation Enveil
organisation LinkedIn
organisation Infection Chain The
organisation PDF
organisation YARA
organisation SecurityPDF Website & Troy
organisation Principal Security
organisation ESET
organisation PHP
organisation RelayShell
organisation DLL
organisation Microsoft Graph API
organisation OneDrive
organisation ForestTiger
organisation ScoringMathTea
organisation SEO
organisation CVE-2025-49113
organisation WordPress
organisation Command
organisation PrestaShop
organisation CMS
organisation SharePoint
organisation UAV
organisation PDB
organisation SecurityAffairs
infrastructure 17 unique server identifiers
organisation Disney
organisation Google
organisation Oracle
organisation Operation DreamJob
organisation National Cyber Security Centre
organisation Lazarus Used Post-Quantum Key Exchange
organisation Kyber/ML-KEM
organisation NIST
organisation GOST-CBC
organisation AES
organisation Mandiant
organisation Smart App Control
organisation Delivery
organisation JPEG
organisation Backdoor Deployment:
organisation ForestTiger’s C2
infrastructure 2.0
organisation DNS
organisation HPC
organisation Important
organisation CVE-2026-59124
organisation HPC Pack
organisation Exchange
organisation Critical
infrastructure 9.1
organisation Microsoft Fixes
organisation RCE
data_breach 570 record
organisation ZDI
infrastructure 9.8 server
organisation Functionality
organisation Microsoft Defender
organisation PPL
organisation AhnLab
organisation DLL Sideloading
organisation PE DLL
organisation the Process PID
organisation PPID
organisation RPC
organisation MISTPEN’s
data_breach 16 byte
organisation Key Exchange
organisation the Microsoft Security Response Center
organisation MSRC
organisation WFP
organisation Kaspersky
organisation SuspendDefender
organisation Troy Backdoor The
organisation Lazarus’
organisation RWX
organisation Compress-Archive
organisation Terminates
organisation WMI
organisation PID
organisation WebShell
organisation Command Type Description Session
organisation Check & cleanup
organisation File-Based Communication Channel
‎August 2026
Threat actors exploited a zero-day vulnerability in Microsoft's Windows Ancillary Function Driver for WinSock, CVE-2026-68820.
vulnerability CVE-2026-68820
tactic Privilege Escalation
infrastructure Windows
organisation Microsoft
organisation Windows Ancillary Function
general_metric 7.0 score
infrastructure 7.0
organisation Patch Tuesday
tactic Remote Code Execution
organisation DNS
organisation SharePoint
organisation Windows, Office
tactic T1584.004 - Server
organisation Teams
organisation Microsoft Patch
‎early 2026
Threat actors exploited a Microsoft Entra ID flaw to target victims in the early 2026 Operation Dream Job campaign.
campaign Operation Dream Job
‎August 25
Threat actors exploited a known vulnerability in Microsoft Entra ID, allowing them to execute arbitrary code on affected systems.
Tactical Metrics
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎3.1
Software Version
Metrics
infrastructure
‎Roundcube
Affected Product
Metrics
infrastructure
17
Unique Server Identifiers
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎2.0
Software Version
Metrics
data_breach
570
Record
Metrics
infrastructure
‎9.1
Software Version
Metrics
infrastructure
10
Server
Metrics
data_breach
16
Byte