Identity, IAM Technologies

Microsoft says Entra ID identity software not exploited, revises CVE

Editor's Note: Microsoft said late on Aug. 21 that an Entra ID flaw was not exploited in the wild. This story underscores that while not as urgent, security teams should still take a maxium-severity flaw in Entra ID seriously.

After warning Aug. 20 that a maximum-severity deserialization flaw in Entra ID was actively exploited, Redmond reversed course Aug. 21 and said there was no active exploitation.

“While it’s also noted on the CVE page, we wanted to call attention to a correction that was made,” said a Microsoft spokesperson. “The company corrected 'Exploited' to 'No' in the CVE. This vulnerability was not exploited in the wild. This is an informational change only.”

In releasing a patch for CVE-2026-69836, Microsoft said the deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Microsoft added that the vulnerability was fully mitigated, so there’s no action for Entra ID users to take.

John Strand, owner of Black Hills Information Secuirty, said while it’s relevant whether or not the Entra ID bug was exploited in the wild, it’s not necessarily relevant from the perspective of how corporate organizations need to look at these classes of identity-based vulnerabilities.

“Once we start seeing these vulnerabilities in a certain class or an API, then there tends to be pile-on vulnerabilities, and I think organizations need to focus more on what their detective controls around that specific API would be to prepare them for what’s going on in the future,” said Strand. “I think it’s a bit weird that Microsoft didn’t necessarily come out and say that everything’s all clear. But also with these types of things, it’s strange to say, but simply because they don’t have any evidence of a breach doesn’t necessarily mean that there’s not a breach.”

Roman Sannikov, global research coordinator at iCounter, said we’re now seeing a genuinely different circumstance from Friday, not a footnote to it.

Sannikov said his original comment was built around one fact: that Microsoft confirmed this was already being exploited in attacks before they patched it. They've now retracted that, said Sannikov, so if there's no confirmed “in-the-wild” exploitation and no public exploit code, the specific thing I was telling teams to go check for, evidence of prior compromise during an active exploitation window, may not exist, because the window itself may not have existed.

Plus, Sannikov pointed out Microsoft never actually closed the loop: “They corrected the exploitation claim, but they never explicitly said 'and therefore, no further action is required because there's no evidence anyone was compromised.’ Those are two different statements, and leaving the second one unsaid is either an oversight or a hedge, and I'm not sure which is worse.”

Sannikov said as a practical matter, security teams shoud still do the same baseline hygiene: a quick review of Entra sign-in logs for anything anomalous in the days before the patch, but the urgency has genuinely changed.

Seemant Sehgal, founder and CEO at BreachLock CEO, added that Microsoft’s clarification removes the urgency associated with a vulnerability that was reportedly being exploited in the wild, but it does not change the severity of the underlying flaw.

“An unauthenticated remote code execution vulnerability in a critical identity platform is still a significant security event,” said Sehgal. “While Microsoft has stated that the issue has been fully remediated and no customer action is required to apply a fix, organizations should still consider reviewing logs and monitoring for unusual authentication or administrative activity during the period before the remediation was deployed. The risk is lower if there is no evidence of active exploitation, but security teams should seek assurance that their environments were not affected before treating the issue as closed."

You can skip this ad in 5 seconds