Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

2026-08-21T14:51:41Z6e7670c1872647081ffeecd814395b94b236753ae9adbfcd85c4b1f93824f1be
CVE-2026-19490CVE-2026-69836AI-agent-securityAI-brand-impersonationCitrix NetScalerDDoSGoogle ColabGoogle GeminiMicrosoft Entra IDVidarauthentication-bypassexploitation-in-the-wildfake-bank-domainsfraudinfostealermalware-distributionphishingpost-quantum-cryptographyremote-code-executionvulnerability

What happened

Help Net Security reports multiple security developments, including a purported critical, actively exploited remote code execution vulnerability in Microsoft Entra ID (CVE-2026-69836, CVSS 10.0), a critical Citrix NetScaler authentication bypass (CVE-2026-19490), malware campaigns impersonating major AI brands, phantom bank phishing infrastructure, and a fake Gemini installer distributing the Vidar infostealer. The feed also covers defensive product releases, AI-agent authorization controls, and post-quantum cryptography migration readiness.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
6e7670c1872647081ffeecd814395b94b236753ae9adbfcd85c4b1f93824f1be
Enrichment time
2026-08-21T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.