Microsoft corrected its Entra ID CVE-2026-69836 advisory on August 21, 2026, to state that the maximum-severity cloud vulnerability was not exploited in the wild. The revision reverses exploitation information that prompted initial reports describing attacks against the identity platform. Microsoft said the change was informational and did not alter the protection status of its hosted service.

CVE-2026-69836 affects Microsoft Entra ID, the cloud identity and access management service formerly called Azure Active Directory. Microsoft published the record on August 20 and credited Microsoft principal security engineer Robert Fitzpatrick with the discovery. The vendor assigned the vulnerability a CVSS 3.1 base score of 10.0 and classified it as critical.

According to Microsoft and the NIST National Vulnerability Database, the flaw is caused by deserialization of untrusted data, tracked under CWE-502. The published description says an unauthorized attacker could execute code over a network. Its CVSS vector indicates network reachability, low attack complexity, no required privileges and no user interaction, with high potential impact to confidentiality, integrity and availability.

Microsoft's August security feed now lists the issue as not publicly disclosed, not exploited and less likely to be exploited in the latest software release. The August 21 revision history explicitly says Microsoft corrected the exploited field to no and that the vulnerability was not used in the wild. NIST's record also carries a CISA assessment showing no known exploitation as of August 21.

The company said it had already fully mitigated CVE-2026-69836 in the Entra ID hosted service and that customers do not need to install an update or take a vulnerability-specific action. No remediation package is listed because Microsoft controls the affected cloud infrastructure. The public records provide no exploit code, indicators of compromise, affected-tenant count or attack chronology.

Security teams should update vulnerability tracking and internal reporting to reflect Microsoft's correction while continuing routine review of Entra ID sign-in, audit and risk logs under established monitoring policies. Defenders can use the Microsoft Security Response Center record and NIST entry as the current references, avoiding operational decisions based on the superseded exploitation status.