Critical 10.0
CVE-2026-69836
Exploitation and In-the-Wild Attacks on CVE-2026-69836 and Related Vulnerabilities
Vendor / product: Microsoft Entra ID, Microsoft SCCM, VMware vCenter, Citrix NetScaler, TrueConf, Zimbra Collaboration Suite, Microsoft Defender, Copilot Personal, Cursor IDE
Event date: 2026-08-20
Victim organization: McDonald's, TCS, Vodafone, HCL Technologies
Public PoC: Yes
First tracked by RiskWire: 2026-08-23
Named threat actors
The GentlemenCl0pLinX CodersSalt TyphoonHead Mare
Sources & citations (4)
- Weekly Cyber Security Newsletter Bulletin – Entra ID RCE, Claude Code Ransomware, T-Mobile Cable, Azure Credential Theft +20 Stories cybersecuritynews.com · 2026-08-23
- Newsletter du podcast RadioCSIRT N°62 radiocsirt.substack.com · 2026-08-23
- Cyberattack Sunday; Aug 16th - 22nd, 2026 latestincyber.substack.com · 2026-08-23
- Ankura CTIX FLASH Update – August 21, 2026 mondaq.com:443 · 2026-08-24
References
See CVE-2026-69836 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →