we_are_coded.by CODE · The world, decoded
БГ
Microsoft

Microsoft corrected its own field: the 10.0 hole in Entra ID was not exploited

MSRC Security Update GuideSecurity

On 20 August Microsoft announced a critical hole in Entra ID with the maximum score of 10.0 and noted in its record that it was being exploited. A day later it corrected the field. The patch is entirely on their side, and for customers there is nothing to do.

In short
  • CVE-2026-69836: deserialisation of untrusted data in Microsoft Entra ID, code execution over the network with no authentication, base score 10.0.
  • Per Microsoft the service is already patched on their side and there is no action for users.
  • On 21 August revision 1.1 corrects the exploited field to No. The number is not in the CISA catalogue.
Checked on21 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

I opened the Microsoft record twice in two days. The second opening said something else.

On 20 August Microsoft published CVE-2026-69836 - a critical hole in Entra ID, the service through which millions of organisations log in to its cloud. The base score is 10.0, the maximum on the scale. The same record had an exploited field with the value yes, and from there came the headlines about the perfect ten under attack.

On 21 August revision 1.1 of the same record came out. Word for word: the field is corrected to no, the vulnerability was not exploited in the wild, the change is informational only.

The facts: CVE-2026-69836 is deserialisation of untrusted data (CWE-502) in Microsoft Entra ID, which lets an unauthorised attacker execute code over the network. Microsoft published it on 20 August 2026, rates it critical with a base value of 10.0 on CVSS 3.1 and a temporal one of 8.7, and marks the exploit code as unproven. In the answers attached to the record Microsoft writes that the vulnerability is already fully mitigated on its side, that there is no action for users of the service, and that the point of the number is transparency. Public disclosure before the bulletin: no. On 21 August 2026 revision 1.1 corrects the exploited field to no, with the text that the hole was not used in real attacks. In the CISA catalogue of known exploited vulnerabilities (version 2026.08.21) this number is not present. Primary source: the record in the Security Update Guide of MSRC.

What 10.0 means exactly here

Deserialisation of untrusted data is an old and very annoying class of mistake. The service receives a packet of data from outside, unpacks it, and while it unpacks it, it lets it turn into a live object in memory. Rig the packet and somebody else's code runs. No password, over the network.

Entra ID is the door. Through it you get into Microsoft 365, into Azure and into the internal applications of a large part of the corporate world. That is why the score is what it is: open that door and there is no second one behind it.

A score of 10.0 says how heavy it would be. It does not say it happened.

Why they tell you at all

Since 2024 Microsoft has issued CVE numbers for holes in its own cloud services too, including when the customer has nothing to patch. This record is exactly that. The patch is theirs, it is done, you have no move. How the hole was used and whether it ever reached data is not said anywhere.

I like this move and I think most cloud providers should copy it. But transparency carries an obligation too: the fields in the record have to be right the first time. One field, wrong for one day, got people out of bed who had nothing to do anyway.

On 21 August The Register came out with a headline that the perfect ten in Entra ID is under attack. I have nothing to hold against them. The bulletin said so.

What I take from this is practical. If you marked this hole as urgent work for Monday, cross it out. And before you wake somebody up in the middle of the night over one field in a bulletin, look at the revision number and the date next to it. Records get corrected. Headlines do not.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Sources
Official primary source
→MSRC Security Update Guide - CVE-2026-69836 (Microsoft Entra ID Remote Code Execution Vulnerability)→MSRC blog - Toward greater transparency: Unveiling Cloud Service CVEs→CISA - Known Exploited Vulnerabilities Catalog
Media confirmation
→The Register (21.08.2026) - the headline that ran on the uncorrected field
Original: https://wearecoded.com/en/articles/entra-id-cve-2026-69836.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news