🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-62869 is a spoofing vulnerability in Azure Entra ID (formerly Azure Active Directory) caused by insufficient verification of data authenticity. An attacker who already has some level of authorised access could exploit this over a network to impersonate another identity or entity. This is particularly concerning given Entra ID’s role as the central identity provider for Microsoft cloud environments, where a spoofed identity could enable lateral movement or unauthorised resource access.

Security Architect’s Take: Review audit logs in Entra ID for anomalous sign-in patterns or unexpected token issuance, and apply any available Microsoft patches or mitigations immediately. Consider tightening Conditional Access policies and enabling anomaly detection alerts while a fix is confirmed to be in place.

Original advisory: CVE-2026-62869 Azure Entra ID Spoofing Vulnerability