Microsoft patched a CVSS 10.0 Entra ID flaw, then corrected the exploitation flag from yes to no
CVE-2026-69836 was an unauthenticated deserialization flaw in Entra ID scoring a perfect 10.0. Microsoft fixed it service-side with no customer action, but first published it marked as exploited, then reversed that a day later.
Microsoft disclosed CVE-2026-69836 on August 20, 2026, a CVSS 10.0 remote code execution flaw in Microsoft Entra ID. The root cause is deserialization of untrusted data (CWE-502) reachable without authentication. Microsoft mitigated it inside its own infrastructure and states no customer action is required. The advisory originally set the "Exploited" field to Yes; on August 21, after The Hacker News queried it, Microsoft corrected the field to No and said the vulnerability was not exploited in the wild. For the roughly 24 hours in between, the public record showed a maximum-severity flaw in a service most enterprises authenticate through as being under active attack.
Why it matters
Two separate things happened here and they deserve separate reactions. The vulnerability itself is the more reassuring half: it was in Microsoft's service, Microsoft fixed it, and there is genuinely nothing to patch. That is the deal a tenant makes when identity moves to a hosted control plane, and on this occasion the deal worked.
The disclosure is the harder half. A maximum-severity flaw in the authentication backbone for most enterprise Microsoft estates was published with an exploitation flag that turned out to be wrong, and the correction came from a journalist asking rather than from a scheduled revision. Teams that ran an incident bridge on August 20 spent it on a fact that was not true. Cloud identity providers have no customer-side patch to gate a response on, so the advisory field is the response trigger, which makes its accuracy load-bearing in a way it never was for on-premises software. The practical takeaway for a security team: for hosted identity, treat a vendor exploitation flag as a signal to verify in your own sign-in logs rather than as a finding, and confirm you can answer "was our tenant affected" from telemetry you hold.
Sources: The Hacker News, Help Net Security
Related on Start with Identity
- BlogKeycloak password reset flaw let anyone skip the email token and take over any account
CVE-2026-18963 is improper state validation in Keycloak's reset-credentials flow. A crafted request jumped the authentication session straight to the password-u
- BlogNetScaler ships a critical authentication bypass affecting Gateway and AAA virtual servers
CVE-2026-19490 (CVSS 9.3) bypasses authentication on NetScaler ADC and Gateway appliances running a Gateway or AAA virtual server, with a SAML action configured
- BlogAzure AD is now Microsoft Entra ID: what actually changed
Microsoft announced the Azure AD to Entra ID rename in July 2023 and finished the visible relabelling by the end of that year. No tenant, protocol, or licence c
- GuideMigrating from AD FS to Microsoft Entra ID
Active Directory Federation Services did its job for a decade, but running your own federation servers now means patching, certificate management, capacity plan
- GuideConditional Access Policies: A Complete Implementation Guide for Microsoft Entra
Master Microsoft Entra conditional access with risk-based policies, device compliance rules, location-based restrictions, and real-world deployment patterns.
- VendorMicrosoft Entra External ID
strong