Cybersecurity
Microsoft patches Entra ID, Azure Arc and Exchange flaws
Microsoft said it had patched five flaws across Entra ID, Azure Arc, Exchange Online and Azure Managed Instance for Apache Cassandra, including issues that allowed code execution and privilege escalation.
- Microsoft said Robert Fitzpatrick found CVE-2026-69836 in Entra ID.
- Microsoft said CVE-2026-69836 let an unauthorised attacker execute code over a network.
- Microsoft also fixed CVE-2026-65816, CVE-2026-69555, CVE-2026-65801 and CVE-2026-65770 in Azure Arc, Exchange Online and Azure Managed Instance for Apache Cassandra.
- Microsoft said exploit code for the flaws was not online and that users did not need to take action because the issues had already been patched.
- On 22 August, the article was updated after Microsoft said it had mistakenly described CVE-2026-69836 as exploited in the wild; it also referred to Microsoft’s September 2025 patch for CVE-2025-55241 and CISA’s active-exploitation notice for a Windows IKE Service Extensions flaw.
Microsoft said it had fixed CVE-2026-69836 in Entra ID. The company said the flaw let an unauthorised attacker run code over a network, and it named Robert Fitzpatrick, a Microsoft principal security engineer, as the person who found it.
Microsoft also said it had patched CVE-2026-65816, CVE-2026-69555, CVE-2026-65801 and CVE-2026-65770. It said the first three let unauthenticated attackers raise privileges remotely in Azure Arc and Exchange Online, while the last allowed remote code execution in Azure Managed Instance for Apache Cassandra.
The company said exploit code for the vulnerabilities was not available online and that customers did not need to take any action because the flaws had already been fully patched. Microsoft said it published the advisories to provide more transparency.
The article said it was later updated after Microsoft said it had mistakenly described CVE-2026-69836 as exploited in the wild. It also noted Microsoft’s September 2025 patch for CVE-2025-55241, which had been reported by Dirk-jan Mollema of Outsider Security, and CISA’s notice that a Windows Internet Key Exchange (IKE) Service Extensions flaw was actively exploited.
Named in this story
People
- Robert Fitzpatrick
- was named as the Microsoft principal security engineer who found CVE-2026-69836
- Dirk-jan Mollema
- reported CVE-2025-55241 to Microsoft
Companies
- Microsoft
- patched the vulnerabilities and issued the advisory
Organisations
- Outsider Security
- reported CVE-2025-55241 to Microsoft through Dirk-jan Mollema
Governments and agencies
- CISA
- tagged a Windows IKE Service Extensions flaw as actively exploited
Products and systems
- Entra ID
- had a flaw that allowed remote code execution
- Azure Arc
- had flaws that allowed remote privilege escalation
- Exchange Online
- had a flaw that allowed remote privilege escalation
- Azure Managed Instance for Apache Cassandra
- had a flaw that allowed remote code execution
- Windows Internet Key Exchange (IKE) Service Extensions
- was identified by CISA as actively exploited
How the source tells it
Mostly a plain security notice with routine severity language and a brief correction note; it did not rely on distinct emotive framing.
No emotive framing was found in the original.