ctipilot.ch

Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0 — a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22.

cve · CVE-2026-69836 contradicted

Coverage timeline
1
first 2026-08-23 → last 2026-08-23
Peak priority
notable
1 notable
Sources cited
2
2 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products
Microsoft Entra ID

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-23/cve-2026-69836-entra-id-exploited-flag-corrected · ATT&CK page ↗

Story timeline

  1. 2026-08-23CVE-2026-69836 — Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later
    trending-vulnerabilitiesA maximum-severity identity-plane CVE with nothing to patch, and two authorities that disagree about whether it was ever exploited

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • euvd.enisa.europa.eu1 (50%)
  • msrc.microsoft.com1 (50%)

explore in graph

Entries about Microsoft Entra ID deserialization of untrusted data (CWE-502), CVSS 3.1 base 10.0 — a cloud-service CVE already mitigated by Microsoft with no tenant action available. Recorded here for the exploitation-status contradiction: MSRC revision 1.1 of 2026-08-21 corrected the record to not-exploited, while ENISA's EU Vulnerability Database still carried it on the exploited feed when checked on 2026-08-22. (1)

2026-08-23 · view entry permalink →

NOTABLECVE-2026-69836NATOA2

CVE-2026-69836 — Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later

Microsoft published CVE-2026-69836 on 2026-08-20 as a deserialization-of-untrusted-data flaw (CWE-502) in Entra ID, rated CVSS 3.1 base 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C and described in a single sentence: "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network" (Microsoft Security Response Center, 2026-08-21). No mechanism, no affected component and no attack path is published beyond that line. This is one of Microsoft's cloud-service CVEs, issued for transparency rather than to drive customer action — its own FAQ states the flaw "has already been fully mitigated by Microsoft. There is no action for users of this service to take", and the record's customerActionRequired field is false (Microsoft Security Response Center, 2026-08-21). There is nothing to patch, nothing to configure, and no version boundary to check.

What makes it worth a defender's attention is the exploitation field, and the fact that two authorities currently give different answers about it. Microsoft's revision history shows the record published at version 1 on 2026-08-20 and revised at version 1.1 the following day with the note "This vulnerability was not exploited in the wild. This is an informational change only" — a correction of the Exploited field (Microsoft Security Response Center, 2026-08-21). The wording only makes sense if the field briefly held some other value during the day the record was live before the correction. The current record is internally consistent with not-exploited: the exploitability assessment reads "Exploitation Less Likely", and the CVSS vector Microsoft itself publishes carries E:U — exploit-code maturity "Unproven".

ENISA's EU Vulnerability Database has not followed. Its record for this CVE (EUVD-2026-63693) was last updated on 2026-08-22, a day after Microsoft's correction, and still carries an exploitedSince value of 2026-08-21 on its exploited-vulnerabilities feed, alongside an EPSS of 1.37 (ENISA EU Vulnerability Database, 2026-08-22). The only reference that record cites is the Microsoft page that now says the opposite. The same feed carries the same field, correctly, for the actively exploited TrueConf Server pair — so the mechanism works; this specific record simply did not get the correction. CISA's Known Exploited Vulnerabilities catalogue does not list the CVE at all, and no research lab or managed-detection vendor has published exploitation telemetry of its own.

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

This vulnerability was not exploited in the wild. This is an informational change only.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take.

Microsoft Security Response Center 2026-08-21
vulnerability23 Aug 04:42ZcontradictedOpen finding ↗