2026-08-23NOTABLEA maximum-severity identity-plane CVE with nothing to patch, and two authorities that disagree about whether it was ever exploited
Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0, a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22.
cve · CVE-2026-69836 contradicted
Coverage
1
first 2026-08-23 → last 2026-09-06
Latest activity
2026-08-23
A maximum-severity identity-plane CVE with nothing to patch, and two authorities that disagree about whether…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, finance, healthcare · regions: europe
Sources cited
3
3 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-69836, newest first. Check the date before acting on an older one.
- If your vulnerability process ranks or escalates on ENISA EUVD's exploited-vulnerabilities feed, reconcile CVE-2026-69836 against the MSRC record before treating it as an exploited finding, and check whether anything downstream already raised it.2026-08-23CVE-2026-69836
Defender insights
What each entry about CVE-2026-69836 tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-23/cve-2026-69836-entra-id-exploited-flag-corrected · ATT&CK page ↗
Entries about Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0, a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- api.first.org1 (33%)
- euvd.enisa.europa.eu1 (33%)
- msrc.microsoft.com1 (33%)
External references
All cited sources (3)
- msrc.microsoft.comprimaryMicrosoft Security Response Centerhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836
- api.first.orgFIRST.org EPSS API, value as of 2026-08-22https://api.first.org/data/v1/epss?cve=CVE-2026-69836&date=2026-08-22
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63693