Microsoft Dropped a CVSS 10 Entra ID RCE — Then Changed Its Mind About Exploitation
- The Mess: Microsoft disclosed CVE-2026-69836, a maximum-severity remote code execution vulnerability in Entra ID. The company initially marked the flaw as exploited in the wild, then changed that status to No and confirmed that it had not been exploited.
- The Damage: The vulnerability received a CVSS 10.0 score and could allow an unauthenticated attacker to execute code remotely inside Microsoft’s cloud identity service. Microsoft Entra ID sits at the authentication layer for Microsoft 365, Azure and countless connected enterprise applications.
- The Fix: Microsoft says the vulnerability has already been fully mitigated on its side. Customers have no patch to install and no action is currently required.
A CVSS 10.0 remote code execution bug in an identity platform is already a serious headline.
Then Microsoft made the story stranger.
The company initially indicated that the vulnerability had been exploited in the wild.
Security news sites reported exactly that.
Then Microsoft changed the exploitation status.
No. Not exploited.
Welcome to the CVE disclosure mess surrounding CVE-2026-69836.
A Maximum-Severity Bug Inside Entra ID
The vulnerability affects Microsoft Entra ID, the cloud identity platform formerly known as Azure Active Directory.
Microsoft describes the issue as deserialization of untrusted data that could allow an unauthorized attacker to execute code over a network.
The CVSS score is 10.0.
The attack vector is network-based.
Attack complexity is low.
No privileges are required.
No user interaction is required.
On paper, that is about as bad as a vulnerability gets.
And this isn’t an ordinary web application.
Entra ID sits in the authentication chain.
Users.
Administrators.
Microsoft 365.
Azure.
Enterprise applications.
Identity is where everything eventually meets.
Microsoft Said It Was Exploited. Then It Didn’t.
The original disclosure created immediate concern because Microsoft’s advisory reportedly marked the vulnerability as Exploited: Yes.
Multiple security publications reported that information.
Then Microsoft corrected the record.
The exploitation status changed to No.
Microsoft subsequently confirmed that CVE-2026-69836 had not been exploited in the wild.
That correction matters.
A CVSS 10 vulnerability is serious.
A CVSS 10 vulnerability actively exploited against Microsoft’s cloud identity infrastructure is an entirely different emergency.
Those are not the same story.
And the first version travelled around the Internet before the correction caught up.
There Is Nothing for Customers to Patch
The other unusual part is the response.
Microsoft says the vulnerability was already fully mitigated inside its service before the public disclosure.
Customers don’t need to download an update.
They don’t need to patch a server.
They don’t need to change an Entra ID setting.
Microsoft released the CVE, according to the company, for transparency.
That’s the advantage of a fully Microsoft-operated cloud service.
When the vulnerable component lives entirely inside the provider’s infrastructure, the provider can fix it centrally.
Of course, that also creates a different problem.
Customers have to trust that the fix reached every relevant component.
There is no version number to check.
No package update.
No reboot.
No satisfying green line in a vulnerability scanner saying:
Patched.
Microsoft says it is fixed.
That’s the patch.
The Technical Details Are Still Thin
Microsoft has disclosed the vulnerability category.
Deserialization of untrusted data.
But the company has not publicly described the vulnerable endpoint, request structure or internal exploit chain.
That means the CVSS score tells us how bad successful exploitation could be.
It doesn’t tell us exactly how an attacker would have reached the vulnerable code.
There is currently no authoritative public exploit chain.
No detailed proof of concept.
No published attack request.
And, following Microsoft’s correction, no confirmed exploitation in the wild.
That leaves defenders with an unusual security story.
Maximum technical severity.
No customer patch.
No public exploit.
No confirmed real-world exploitation.
And a disclosure that briefly said the exact opposite.
The Bigger Problem Is Trust
Entra ID is not a forgotten server in a data centre.
It’s cloud infrastructure trusted by organizations around the world.
A successful RCE inside an identity platform would potentially have consequences far beyond one vulnerable application.
That doesn’t mean CVE-2026-69836 automatically gave attackers control of every Microsoft tenant.
Microsoft has not publicly described such an attack chain.
But that’s exactly why the vulnerability attracted attention.
Identity infrastructure is a high-value target.
When identity breaks, the blast radius can become very large very quickly.
Bugstoday Opinion
The CVE itself is serious.
The disclosure process is the interesting part.
Microsoft initially indicated exploitation.
The security industry reacted.
News spread.
Then the exploitation flag changed to No.
That’s not just an embarrassing metadata correction.
For defenders, exploitation status changes prioritization.
A critical vulnerability might mean:
Schedule the incident review.
A critical vulnerability actively exploited in the wild means:
Start the incident review now.
Those are very different decisions.
CVE-2026-69836 remains a CVSS 10.0 remote code execution vulnerability in one of Microsoft’s most important cloud services.
But based on Microsoft’s corrected information, it should not currently be described as actively exploited.
Bugstoday verdict: CVSS 10 tells you how bad exploitation could be. It doesn’t tell you that exploitation happened. And sometimes even the original advisory gets that part wrong.
Today’s Bugs. Tomorrow’s Breaches.




