< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Microsoft faces critical RCE vulnerabilities in SharePoint and Entra ID

Microsoft is addressing two critical remote code execution (RCE) vulnerabilities that are being actively exploited in the wild.

One flaw, identified as CVE-2026-50522, affects Microsoft SharePoint Server. With a CVSS score of 9.8, this vulnerability involves the deserialization of untrusted data. It allows attackers to execute code remotely without user interaction, potentially compromising on-premises installations. Researchers have noted attacks aimed at obtaining Internet Information Services (IIS) machine keys, which could allow attackers to maintain persistent access even after security updates are applied.

A second critical vulnerability, CVE-2026-69836, affects Microsoft Entra ID, the company’s cloud-based identity and access management platform. This flaw also stems from untrusted data deserialization. Because Entra ID manages authentication for Microsoft 365 and Azure, exploitation could allow attackers to hijack authentication tokens or manipulate access policies across entire organizational ecosystems. Microsoft confirmed that this vulnerability was being exploited before its public disclosure.

Entities

Microsoft · Microsoft Entra ID · Microsoft SharePoint