ctipilot.ch
← Back to the live brief
NOTABLECVE-2026-69836NATOA2vulnerability

CVE-2026-69836 — Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later

discovered 2026-08-23 04:42 UTCrun 2026-08-23T0409Z-intel2 sourcescontradicted

Microsoft published CVE-2026-69836 on 2026-08-20 as a deserialization-of-untrusted-data flaw (CWE-502) in Entra ID, rated CVSS 3.1 base 10.0 with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C and described in a single sentence: "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network" (Microsoft Security Response Center, 2026-08-21). No mechanism, no affected component and no attack path is published beyond that line. This is one of Microsoft's cloud-service CVEs, issued for transparency rather than to drive customer action — its own FAQ states the flaw "has already been fully mitigated by Microsoft. There is no action for users of this service to take", and the record's customerActionRequired field is false (Microsoft Security Response Center, 2026-08-21). There is nothing to patch, nothing to configure, and no version boundary to check.

What makes it worth a defender's attention is the exploitation field, and the fact that two authorities currently give different answers about it. Microsoft's revision history shows the record published at version 1 on 2026-08-20 and revised at version 1.1 the following day with the note "This vulnerability was not exploited in the wild. This is an informational change only" — a correction of the Exploited field (Microsoft Security Response Center, 2026-08-21). The wording only makes sense if the field briefly held some other value during the day the record was live before the correction. The current record is internally consistent with not-exploited: the exploitability assessment reads "Exploitation Less Likely", and the CVSS vector Microsoft itself publishes carries E:U — exploit-code maturity "Unproven".

ENISA's EU Vulnerability Database has not followed. Its record for this CVE (EUVD-2026-63693) was last updated on 2026-08-22, a day after Microsoft's correction, and still carries an exploitedSince value of 2026-08-21 on its exploited-vulnerabilities feed, alongside an EPSS of 1.37 (ENISA EU Vulnerability Database, 2026-08-22). The only reference that record cites is the Microsoft page that now says the opposite. The same feed carries the same field, correctly, for the actively exploited TrueConf Server pair — so the mechanism works; this specific record simply did not get the correction. CISA's Known Exploited Vulnerabilities catalogue does not list the CVE at all, and no research lab or managed-detection vendor has published exploitation telemetry of its own.

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

This vulnerability was not exploited in the wild. This is an informational change only.

This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take.

Microsoft Security Response Center 2026-08-21

Defender actions

  • If your vulnerability process ranks or escalates on ENISA EUVD's exploited-vulnerabilities feed, reconcile CVE-2026-69836 against the MSRC record before treating it as an exploited finding — and check whether anything downstream already raised it.

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.