Start with Identity
← Blog
News

Microsoft patched a CVSS 10.0 Entra ID flaw, then corrected the exploitation flag from yes to no

CVE-2026-69836 was an unauthenticated deserialization flaw in Entra ID scoring a perfect 10.0. Microsoft fixed it service-side with no customer action, but first published it marked as exploited, then reversed that a day later.

By SWI Community TeamAug 21, 2026Updated Aug 29, 2026

Microsoft disclosed CVE-2026-69836 on August 20, 2026, a CVSS 10.0 remote code execution flaw in Microsoft Entra ID. The root cause is deserialization of untrusted data (CWE-502) reachable without authentication. Microsoft mitigated it inside its own infrastructure and states no customer action is required. The advisory originally set the "Exploited" field to Yes; on August 21, after The Hacker News queried it, Microsoft corrected the field to No and said the vulnerability was not exploited in the wild. For the roughly 24 hours in between, the public record showed a maximum-severity flaw in a service most enterprises authenticate through as being under active attack.

Why it matters

Two separate things happened here and they deserve separate reactions. The vulnerability itself is the more reassuring half: it was in Microsoft's service, Microsoft fixed it, and there is genuinely nothing to patch. That is the deal a tenant makes when identity moves to a hosted control plane, and on this occasion the deal worked.

The disclosure is the harder half. A maximum-severity flaw in the authentication backbone for most enterprise Microsoft estates was published with an exploitation flag that turned out to be wrong, and the correction came from a journalist asking rather than from a scheduled revision. Teams that ran an incident bridge on August 20 spent it on a fact that was not true. Cloud identity providers have no customer-side patch to gate a response on, so the advisory field is the response trigger, which makes its accuracy load-bearing in a way it never was for on-premises software. The practical takeaway for a security team: for hosted identity, treat a vendor exploitation flag as a signal to verify in your own sign-in logs rather than as a finding, and confirm you can answer "was our tenant affected" from telemetry you hold.

Sources: The Hacker News, Help Net Security

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.