A CVSS 10.0 remote code execution flaw in the identity layer of half the corporate world

and there is no patch for you to install.

CVE-2026-69836, disclosed by Microsoft on August 20: unauthenticated RCE in Entra ID via deserialization of untrusted data. Already fully mitigated in the service. No customer action required.

WHAT ACTUALLY HAPPENED

The flaw is a CWE-502 issue — untrusted input turned into live objects without validation — reachable over the network with no credentials and no user interaction. Hence the perfect 10.0.

It sits in Entra ID: the identity backbone behind Microsoft 365, Azure and every SaaS app federated to it.

Microsoft found it internally, remediated it in the service, and published the CVE for transparency.

One complication: the advisory initially carried "Exploited: Yes". After press enquiries, Microsoft corrected the flag to "No" on August 21 — after a day of alarm across every security feed and SOC that automates on that field.

WHY A FLAW YOU CANNOT PATCH IS STILL YOUR PROBLEM

Cloud-fixed vulnerabilities break the model most security programmes are built on. There is no KB to deploy, no version to verify, no scan result to close. Your vulnerability management process has nothing to grip.

But your exposure was real. During the vulnerable window, an unauthenticated attacker could in principle reach the system that issues tokens for your entire estate. You were not told at the time, and you cannot go back and check.

This is the governance gap: risk that lives in your provider's code, is remediated on your provider's timeline, and is disclosed at your provider's discretion — while the consequences remain entirely yours.

The lesson is not "patch faster". It is that part of your attack surface now sits permanently outside your visibility — and your controls must assume it.

WHAT TO DO NOW

DO NOT AUTOMATE PANIC ON VENDOR FLAGS — the "Exploited" field flipped in 24 hours, so build human verification into critical-severity triage.

TRACK PROVIDER-REMEDIATED CVES ANYWAY — log them in your risk register with dates, even when there is no action, because auditors and regulators will ask.

ASSUME IDENTITY CAN FAIL — enforce conditional access, phishing-resistant MFA and privileged access separation so one token issuer is not the only thing between attacker and estate.

MONITOR ENTRA SIGN-IN AND AUDIT LOGS INDEPENDENTLY — your own detection is the only coverage you control over your provider's blind spots.

You outsourced the infrastructure. You did not outsource the consequences.

How does your risk register handle a critical vulnerability with no patch and no action for you to take?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.