CVE-2026-33843Active Exploitation(microsoft / entra_id)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft entra_id systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • entra_id

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
entra_id

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-23: 2Mentions · 2026-05-27: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-27: 105-2305-27
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-232
Active Exploitation1Disclosure1
2026-05-271
Patch1
Full discourse3 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-33843 (CVSS 9.1) - Authentication bypass in Microsoft Azure AD B2C allows unauthorized privilege escalation over network. No user interaction required. Patch immediately. #CVE #PatchNow #CyberSecurity https://t.co/E7Yb938WGc

    Post summary

    CVE-2026-33843 is a critical authentication bypass in Microsoft Azure AD B2C, enabling privilege escalation over the network with no user interaction; a patch is urgently required.

    1002089
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33843 Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-33843

    Post summary

    A newly disclosed authentication bypass in Microsoft Azure AD B2C (CVE‑2026‑33843) allows privilege escalation via an alternate path, but no PoC, exploit, or patch is provided.

    00010184
    57.5K followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-33843 in Microsoft Azure Active Directory B2C is being weaponized: attackers can elevate privileges, risking critical data breaches. Patch now to prevent exploitation. #NerdieNews #CyberSecurity #ThreatIntel https://t.co/VnytW1L8YU

    Post summary

    The tweet warns that CVE‑2026‑33843 in Microsoft Azure AD B2C is being weaponized, enabling privilege escalation attacks, and urges immediate patching to mitigate the threat.

    0000060
    64 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftentra_id---

Explore more