Microsoft patches a 10.0-rated RCE in Entra ID and tells customers to do nothing
A deserialization flaw in Entra ID, Microsoft’s cloud identity service, allowed unauthenticated remote code execution — rated CVSS 10.0 and fixed server-side with no customer action. CISOs need to understand what "no action required" actually demands of them.