CVE-2026-40379General(microsoft / entra_id)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft entra_id systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • entra_id

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-09-28)
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
entra_id

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-09: 1Mentions · 2026-05-13: 1Mentions · 2026-05-16: 1Mentions · 2026-05-19: 1Mentions · 2026-09-28: 2Active Exploitation · 2026-05-09: 1Patch / Workaround · 2026-05-16: 1Patch / Workaround · 2026-09-28: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-16: 1Technical Details · 2026-05-19: 1Technical Details · 2026-09-28: 105-0905-1305-1605-1909-28
Signal classification3 categories
General
240.0%
Patch
240.0%
Active Exploitation
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-091
Active Exploitation1
2026-05-131
General1
2026-05-161
Patch1
2026-05-191
General1
2026-09-282
Patch1
Full discourse6 posts
  • Paco Sepúlveda@FMSepulveda

    CVE-2026-40379 puts the focus where it hurts most: Azure ESTS. If the token provider can be deceived, the impact multiplies across all apps that “trust by default” in Entra ID. Real defense starts in how you validate each token in your APIs. 🔗 https://cloudsecurityinpractice.com/en/spoofing-in-azure-ests-the-core-of-authentication-at-risk/

    1000049
    1.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    🚨 CVE-2026-40379 (Azure Entra ID ESTS, CVSS 9.3): Unauth token spoofing → Entra ID bypass → attacker accesses all M365, Azure & Teams tenants. Every Microsoft cloud org exposed. Patched May 12 Patch Tuesday — most still unpatched. Admins: apply NOW. #ZeroDay #EntraID

    Post summary

    The tweet alerts that CVE‑2026‑40379, a high‑severity Azure Entra ID flaw, allows unauthenticated token spoofing and tenant bypass, urging admins to apply the patch released on May 12.

    0001097
    226 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-34327 8.2 Microsoft パートナー センター ・CVE-2026-35428 9.6 Azure Cloud Shell ・CVE-2026-40379 9.3 Azure Entra ID ・CVE-2026-41105 8.1 Azure 通知サービス ・CVE-2026-42826 10  Azure DevOps

    Post summary

    The tweet enumerates several CVEs and their severity ratings but does not provide exploitation details, patches, or evidence of active attacks.

    10000111
    85 followersView on X
  • Paco Sepúlveda@FMSepulveda
    Patch

    CVE-2026-40379 pone el foco donde más duele: Azure ESTS. Si el proveedor de tokens puede ser engañado, el impacto se multiplica en todas las apps que “confían por defecto” en Entra ID. La defensa real empieza en cómo validas cada token en tus APIs. 🔗 https://cloudsecurityinpractice.com/spoofing-azure-ests-autenticacion-en-riesgo/

    Post summary

    The post highlights CVE-2026-40379 targeting Azure ESTS token spoofing risks and emphasizes token validation in APIs as the primary defense, linking to an external article for further details.

    0000051
    1.1K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-40379: Azure Entra ID Information Exposure Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04h4P360

    Post summary

    The snippet references CVE-2026-40379 as an Azure Entra ID information exposure vulnerability but does not provide details on exploitation, patches, or PoCs.

    0000044
    31 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Microsoft Enterprise Security Token Service (CVE-2026-40379) https://vuldb.com/vuln/362021/cti

    Post summary

    Multiple offensive actors are actively exploiting CVE-2026-40379 against Microsoft Enterprise Security Token Service, with no PoC, exploit code, patch, or technical details disclosed.

    0000068
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftentra_id---

Explore more