HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Entra ID — Microsoft Entra ID Deserialization of Untrusted Data Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Analysis

Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. Added to CISA Known Exploited Vulnerabilities catalog on 2026-08-21. Remediation due: 2026-08-24.

Indicators of Compromise (1)

CVE (1)
CVE-2026-69836
Source Attribution

Originally published by CISA KEV on Aug 21, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-101090 — Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect e...

Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard_host setting is empty, /api/v1/oauth2/{provider} (cmd/dashboard/controller/oauth2.go) reflects the attacker-supplied HTTP Host header into the redirect_uri sent to the identity provider instead of falling back to the configured install_host. An attacker who induces a victim to b

CVE-2026-101090
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-101084 — obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-co...

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Attackers can bypass authorization checks to access and manipulate sensitive backend systems through MCP tool calls using stored OAuth credentials.

CVE-2026-101084
NIST NVD
CRITICALVulnerabilityNEW

NVD CRITICAL: CVE-2026-101065 — Obot is an open-source AI agent/MCP platform. In all versions up to and includin...

Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart command documented in the README starts the container listening on 0.0.0.0:8080 with authentication disabled by default. When authentication is disabled, every request is mapped to a synthetic "nobody" user that holds the Owner and Admin roles, so any unauthenticated party who ca

CVE-2026-101065
NIST NVD