Microsoft Entra ID Deserialization of Untrusted Data Vulnerability
Microsoft · Entra ID
Date added (CISA)
2026-08-21
Remediation due
2026-08-24
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.