---
schema: 1
kind: vulnerability
title: "CVE-2026-69836 — Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later"
headline: "A maximum-severity identity-plane CVE with nothing to patch, and two authorities that disagree about whether it was ever exploited"
summary: >
  Microsoft published CVE-2026-69836 on 2026-08-20, a CWE-502 deserialization flaw in Entra ID rated CVSS 3.1 base 10.0 and described only as letting an unauthorized attacker execute code over a network. It is a cloud-service CVE issued under Microsoft's transparency programme: the fix was applied to Microsoft's own infrastructure before disclosure, so no tenant has anything to install. The operationally relevant part is the exploitation field — MSRC's revision 1.1 of 2026-08-21 corrected the record to state the flaw was not exploited in the wild, while ENISA's EU Vulnerability Database, re-synced on 2026-08-22, still carries it on the exploited feed with an exploited-since date of 2026-08-21. Any vulnerability process that ranks on the EUVD exploited feed will treat this CVE as exploited; the vendor that owns the record says it was not.
discovered_at: "2026-08-23T04:42:00Z"
event_date: "2026-08-21"
run_id: 2026-08-23T0409Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, identity, cloud, rce, pre-auth, patch-available]
regions: [global, europe]
sectors: [public-sector, finance, healthcare, telco]
entities: []
techniques: [T1190]
affected_products: ["Microsoft Entra ID"]
cves:
  - id: CVE-2026-69836
    cvss: "10.0"
    epss: "0.0137"
    type: deserialization
    vector: zero-click
    auth: pre-auth
    status: [patch-available]
    affected: "Microsoft Entra ID service (cloud-side; no customer-installable component)"
    fixed: "mitigated by Microsoft on its own infrastructure before disclosure — no tenant action exists"
sources:
  - url: "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836"
    publisher: "Microsoft Security Response Center"
    date: "2026-08-21"
    role: primary
  - url: "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63693"
    publisher: "ENISA EU Vulnerability Database"
    date: "2026-08-22"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network."
    publisher: "Microsoft Security Response Center"
  - quote: "This vulnerability was not exploited in the wild. This is an informational change only."
    publisher: "Microsoft Security Response Center"
  - quote: "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take."
    publisher: "Microsoft Security Response Center"
verification: contradicted
sourcing_note: >
  The two authorities disagree and this entry reports both rather than choosing. Microsoft is the
  issuing CNA and the operator of the affected service, so its corrected record is the stronger
  position on the exploitation question; ENISA's database is recorded as it actually stood on
  2026-08-23. Both records were read directly on 2026-08-23 — the MSRC entry through the Security
  Update Guide API, because the web record is a client-rendered application that returns no content
  to a plain fetch, and the ENISA record from its exploited-vulnerabilities listing.
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "If your vulnerability process ranks or escalates on ENISA EUVD's exploited-vulnerabilities feed, reconcile CVE-2026-69836 against the MSRC record before treating it as an exploited finding — and check whether anything downstream already raised it."
updates:
  - at: "2026-09-06T13:50:00Z"
    run_id: 2026-09-06T1308Z-audit
    type: correction
    summary: >
      The EPSS recorded for CVE-2026-69836 was ENISA EUVD's percentage rendering (1.37) rather than
      the probability the field holds. EUVD publishes EPSS multiplied by one hundred, so the value is
      a probability of 0.0137. Corrected in the CVE record and in the body sentence that quoted the
      bare number.
    fields: [cves, body, sourcing_note]
migrated_from: null
---

Microsoft published CVE-2026-69836 on 2026-08-20 as a deserialization-of-untrusted-data flaw (CWE-502) in Entra ID, rated CVSS 3.1 base 10.0 with the vector `AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C` and described in a single sentence: *"Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network"* ([Microsoft Security Response Center, 2026-08-21](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836)). No mechanism, no affected component and no attack path is published beyond that line. This is one of Microsoft's cloud-service CVEs, issued for transparency rather than to drive customer action — its own FAQ states the flaw *"has already been fully mitigated by Microsoft. There is no action for users of this service to take"*, and the record's `customerActionRequired` field is false ([Microsoft Security Response Center, 2026-08-21](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836)). There is nothing to patch, nothing to configure, and no version boundary to check.

What makes it worth a defender's attention is the exploitation field, and the fact that two authorities currently give different answers about it. Microsoft's revision history shows the record published at version 1 on 2026-08-20 and revised at version 1.1 the following day with the note *"This vulnerability was not exploited in the wild. This is an informational change only"* — a correction of the Exploited field ([Microsoft Security Response Center, 2026-08-21](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69836)). The wording only makes sense if the field briefly held some other value during the day the record was live before the correction. The current record is internally consistent with not-exploited: the exploitability assessment reads "Exploitation Less Likely", and the CVSS vector Microsoft itself publishes carries `E:U` — exploit-code maturity "Unproven".

ENISA's EU Vulnerability Database has not followed. Its record for this CVE (EUVD-2026-63693) was last updated on 2026-08-22, a day *after* Microsoft's correction, and still carries an `exploitedSince` value of 2026-08-21 on its exploited-vulnerabilities feed, alongside an EPSS probability of 0.0137, which EUVD renders as the percentage 1.37 ([ENISA EU Vulnerability Database, 2026-08-22](https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-63693)). The only reference that record cites is the Microsoft page that now says the opposite. The same feed carries the same field, correctly, for the actively exploited TrueConf Server pair — so the mechanism works; this specific record simply did not get the correction. CISA's Known Exploited Vulnerabilities catalogue does not list the CVE at all, and no research lab or managed-detection vendor has published exploitation telemetry of its own.

**Defender takeaway:** the practical consequence is not exposure but triage accuracy. A vulnerability-management process that ingests the EUVD exploited feed as its European counterpart to CISA KEV — a reasonable and increasingly common design — will currently rank a maximum-severity identity-plane CVE as confirmed-exploited when the issuing vendor states it was not, and will do so for a flaw where no remediation action exists to take in response. That is wasted escalation on an item nobody can act on, and it is the second-order cost of automated exploitation feeds: they inherit corrections only as fast as they re-sync, and a re-sync that leaves the field unchanged is indistinguishable from a re-sync that confirmed it. Where an exploited flag drives an out-of-band process, check it against the record that issued the CVE before spending the shift on it.

## Correction — 2026-09-06T13:50:00Z

The EPSS figure quoted from ENISA's EU Vulnerability Database record was its percentage rendering, not the probability the figure names. EUVD's API returns EPSS multiplied by one hundred, so the 1.37 on that record is an exploitation probability of 0.0137, which FIRST.org's own value for the same day corroborates ([FIRST.org EPSS API, value as of 2026-08-22](https://api.first.org/data/v1/epss?cve=CVE-2026-69836&date=2026-08-22)). This does not touch the entry's finding, which is about EUVD's exploited flag rather than its score: that flag still contradicts Microsoft's own corrected record.
