Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-62916

Authentication Bypass via Alternate Path in Microsoft Entra ID

Microsoft Entra ID authentication bypass via alternate path lets unauthenticated attackers escalate privileges over a network. CVSS 9.1 critical. Patch available.

cat cve-2026-62916.json
Vendor
Microsoft
Product
Microsoft Entra ID
CVSS
9.1
EPSS (exploit probability)
0.6%
Status
patched
Published

CVE-2026-62916 is a CVSS 9.1 critical authentication bypass (CWE-288) in Microsoft Entra ID, disclosed September 3, 2026. An unauthenticated remote attacker can reach a privileged Entra ID function through an alternate authentication path, bypassing the expected credential check and gaining elevated access over a network.

Microsoft has released a patch. Organizations using Entra ID should apply the update and review the MSRC advisory for affected configurations and patch scope.

This is the second critical authentication flaw in Entra ID in three weeks. CVE-2026-69836 scored CVSS 10.0 and reached CISA’s Known Exploited Vulnerabilities catalog in mid-August following confirmed active exploitation. CVE-2026-62916 has not been added to the KEV catalog as of September 5, 2026, and Microsoft’s advisory does not report confirmed exploitation in the wild.