2026-08-23 · view entry permalink →
CVE-2026-69836 — Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later
Microsoft published CVE-2026-69836 on 2026-08-20 as a deserialization-of-untrusted-data flaw (CWE-502) in Entra ID, rated CVSS 3.1 base 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C and described in a single sentence: "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network" (Microsoft Security Response Center, 2026-08-21). No mechanism, no affected component and no attack path is published beyond that line. This is one of Microsoft's cloud-service CVEs, issued for transparency rather than to drive customer action — its own FAQ states the flaw "has already been fully mitigated by Microsoft. There is no action for users of this service to take", and the record's customerActionRequired field is false (Microsoft Security Response Center, 2026-08-21). There is nothing to patch, nothing to configure, and no version boundary to check.
What makes it worth a defender's attention is the exploitation field, and the fact that two authorities currently give different answers about it. Microsoft's revision history shows the record published at version 1 on 2026-08-20 and revised at version 1.1 the following day with the note "This vulnerability was not exploited in the wild. This is an informational change only" — a correction of the Exploited field (Microsoft Security Response Center, 2026-08-21). The wording only makes sense if the field briefly held some other value during the day the record was live before the correction. The current record is internally consistent with not-exploited: the exploitability assessment reads "Exploitation Less Likely", and the CVSS vector Microsoft itself publishes carries E:U — exploit-code maturity "Unproven".
ENISA's EU Vulnerability Database has not followed. Its record for this CVE (EUVD-2026-63693) was last updated on 2026-08-22, a day after Microsoft's correction, and still carries an exploitedSince value of 2026-08-21 on its exploited-vulnerabilities feed, alongside an EPSS of 1.37 (ENISA EU Vulnerability Database, 2026-08-22). The only reference that record cites is the Microsoft page that now says the opposite. The same feed carries the same field, correctly, for the actively exploited TrueConf Server pair — so the mechanism works; this specific record simply did not get the correction. CISA's Known Exploited Vulnerabilities catalogue does not list the CVE at all, and no research lab or managed-detection vendor has published exploitation telemetry of its own.
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
This vulnerability was not exploited in the wild. This is an informational change only.
This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take.