CVE-2026-42901Disclosure(microsoft / entra_id)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft entra_id systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • entra_id

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-05-23); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
entra_id

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-05-23: 4Mentions · 2026-05-27: 2Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-23: 2Technical Details · 2026-05-27: 105-2305-27
Signal classification4 categories
Disclosure
350.0%
Active Exploitation
116.7%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-234
Active Exploitation1Disclosure3
2026-05-272
General1Patch1
Full discourse6 posts
  • DailyCVE@dailycve
    General

    🔴 #Microsoft Entra ID, Privilege Escalation, #CVE-2026-42901 (Critical) https://dailycve.com/microsoft-entra-id-privilege-escalation-cve-2026-42901-critical/

    Post summary

    The tweet simply points to an article about a critical privilege‑escalation CVE in Microsoft Entra ID without providing further technical, exploit, or patch details.

    0000052
    207 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-42901 - CVSS 10.0 Origin validation flaw in Microsoft Entra ID enables unauthenticated privilege escalation over network. No user interaction required. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel https://t.co/xmvMUUreYI

    Post summary

    The tweet highlights a critical CVE-2026-42901 with an unauthenticated privilege escalation flaw and urges immediate patching, but no PoC or active exploitation details are provided.

    0000056
    30 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Microsoft Entra (CVE-2026-42901) https://vuldb.com/vuln/365294/cti

    Post summary

    Security analysts report increased actor activity targeting Microsoft Entra CVE-2026-42901, indicating potential active exploitation, though no PoC, exploit code, patch, or detailed technical data is supplied.

    0000068
    2.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42901 Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-42901

    Post summary

    The post announces a new privilege‑escalation CVE (CVE‑2026‑42901) in Microsoft Entra ID, describing the error type but providing no exploitation code, patches, or evidence of active attacks.

    00000189
    57.5K followersView on X
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Disclosure

    Critical vulns: Microsoft Exchange zero-day (CVE-2026-42897) allows mailbox compromise. AI-gen 2FA bypass & new Azure/Entra ID (CVE-2026-42901) flaws threaten data privacy/integrity. Patch DNS! #Cybersecurity #ZeroDay #News

    Post summary

    The note alerts on two newly disclosed Microsoft Exchange vulnerabilities, describing their potential impact on mailbox security and data integrity, and urges a DNS patch.

    00000159
    14 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Microsoft Entra (CVE-2026-42901) https://vuldb.com/vuln/365294

    Post summary

    The text announces an increased severity for CVE-2026-42901 affecting Microsoft Entra and links to a database page, without providing technical details, PoC, exploit code, or evidence of active exploitation.

    0000074
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftentra_id---

Explore more