Identity - 4 min read - 22 August 2026

Microsoft rated its own Entra ID bug 'exploited in the wild.' Hours later, the advisory quietly said otherwise.

CVE-2026-69836 is a maximum-severity, CVSS 10.0 deserialization flaw in Entra ID that needed no authentication to reach. Microsoft's own principal security engineer found it, the company says it was already fixed server-side before anyone outside Microsoft knew it existed, and on 21 August the exploitation field on the advisory changed from Yes to No within the same news cycle.

Entra ID advisories don't usually make for gripping reading, but CVE-2026-69836 is an odd one. It's a deserialization of untrusted data flaw - Microsoft's own wording is "allows an unauthorized attacker to execute code over a network" - sitting in the identity service that gates sign-in for Microsoft 365, Azure and a long tail of third-party applications that trust it as their identity provider. It scored a clean 10.0 on CVSS: no authentication, no user interaction, full compromise. Microsoft's Robert Fitzpatrick, a principal security engineer at the company, is credited with finding it, and the advisory states the vulnerability was fully mitigated on Microsoft's side before publication, with no action required from tenants.

Yes, then No, on the same day

What makes this one worth a second look isn't the score, it's the exploitation field. When the advisory first went out on 21 August, it flagged the flaw as exploited in the wild - the kind of line that gets a vulnerability forwarded around security Slack channels within minutes. Later the same day, that field changed to No, with Microsoft telling reporters the vulnerability "was not exploited in the wild" after being asked to clarify. A spokesperson's follow-up framed the CVE's existence as a transparency measure: "We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency." The Hacker News covered the flip, and Help Net Security's writeup lines up the same detail. Whichever version is accurate, Microsoft hasn't published how the bug was found in the first place, who if anyone tried to use it, or what a working exploit chain would have looked like - which for a cloud identity service is precisely the part a customer can't independently verify.

Why a bug in the identity plane is a different category of risk

Entra ID sits in an unusual position: it isn't an application with a blast radius of its own, it's the thing that decides whether every other application should trust the person in front of it. A deserialization flaw there is dangerous less because of any one payload and more because of what a successful exploit chain could plausibly reach next - service principal credentials, conditional access policy, federation trust with connected apps. Microsoft's line that "no action for users of this service to take" is almost certainly true in the narrow, technical sense: the flaw lived server-side, and a server-side fix closes it without a tenant doing anything. But that's a statement about the vulnerability, not about what a determined attacker might already have done with it before the field briefly said Yes.

What "already mitigated" doesn't cover

A cloud provider patching its own multi-tenant service is exactly the model we want for infrastructure-level flaws - it's faster and more reliable than waiting on every customer to apply an update. The gap it leaves is visibility: Microsoft's assurance covers whether the vulnerability itself is still exploitable, not whether your specific tenant's sign-in and audit history shows anything unusual from the window before the fix landed. That's a question only your own logs can answer, and it's a habit worth having regardless of how any single advisory's exploitation field gets resolved - not because Entra ID is unusually risky, but because it's exactly the kind of infrastructure where identity-tier reviews belong in the same operating rhythm as patching, which is the broader case we make in our piece on identity and access modernisation.

  • Check the Microsoft 365 admin center message centre for any tenant-specific notice tied to CVE-2026-69836, rather than relying on the public advisory alone.
  • Review Entra ID sign-in and audit logs for the days around 21 August 2026 for anomalous service principal activity, unexpected app consent grants, or unfamiliar administrative actions.
  • Confirm conditional access policies and federation trust relationships with third-party applications haven't changed unexpectedly.
  • Don't read "no user action required" as "nothing to review" - it describes the patch, not your tenant's exposure window.
  • Where Entra ID underpins access to regulated or high-value systems, fold an identity-tier log review into your routine incident-readiness checks, not just your patch cadence.

A same-day reversal on whether a maximum-severity identity flaw was actively exploited is the sort of detail that's easy to miss once the field quietly changes back. If you'd like help building the log-review habits that don't depend on a vendor's advisory staying consistent, email sales@halfteck.com.

Explore more resources

Browse our full library of enterprise cloud, software, data and AI content.

View all resources