Entra ID Scored a Perfect Ten, and Identity Security Posture Management Caught It in Time
A single deserialisation bug in Entra ID scored the highest severity rating CVSS allows, and Microsoft closed it before a single attacker got near. That is not luck, it is the difference identity security posture management makes when identity is the whole perimeter now.
By Katie Delaney · 2026-08-25 · 13 min read
What CVE-2026-69836 actually is, and why identity security posture management almost mattered so much#
A flaw scored the maximum severity CVSS allows. Nobody got to use it.
Somewhere in the identity backbone of Microsoft 365 and Azure sign-in, a single flaw sat waiting for a request nobody had to authenticate first. Microsoft's own security advisory confirms CVE-2026-69836 landed a CVSS 3.1 base score of 10.0, the ceiling the scale allows, inside Entra ID, the cloud identity platform that decides who gets through the door for millions of organisations. That is the sharpest possible answer to the question every identity security posture management programme exists to ask: what happens in the moment before anyone notices?
The bug itself is a deserialisation-of-untrusted-data flaw, catalogued as CWE-502 by the National Vulnerability Database's entry for CVE-2026-69836. In plain fox terms, Entra ID was, in one code path, willing to unpack a parcel from a stranger and run whatever was folded inside it: no password, no prompt, no proof of who sent it. NVD's own vector string, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, reads like a checklist of everything a defender dreads: reachable over the network, low attack complexity, no privileges required, no user interaction, and complete loss of confidentiality, integrity and availability if it ever landed.
Ten out of ten, and nothing happened#
Here is the correction worth printing in full, because the headline writes itself the wrong way round: Microsoft's advisory states plainly that CVE-2026-69836 was not publicly disclosed before the patch, was not exploited in the wild (“Exploited: No”), and is “already fully mitigated by Microsoft, no action required from users.” Help Net Security's original report, published 21 August 2026 after disclosure the day before, tells the same quiet timeline. This was never an active attack. It was a maximum-severity flaw closed calmly before it became one, which is a duller story than a breach and a far better one for every organisation that runs its sign-in through Entra ID.
Microsoft says Entra ID identity software not exploited, revises CVE
NVD's own CISA enrichment adds the detail that makes the patch timing matter: the attack pattern is rated ‘automatable’, and the potential impact, had it ever been used, is rated ‘total’. Automatable means a script could have found and used the flaw without a human steering each step. Total means there was no partial version of this compromise on offer: an attacker who reached it would have reached everything Entra ID protects. That pairing, automatable and total, is exactly what turns one CVE into the kind of story a boardroom asks about at the next meeting.
None of that changes the maths for the next flaw, or the one after it. Entra ID sits underneath sign-in for Microsoft 365 and Azure across an enormous share of the working world, which is exactly why cloud identity security has become the trail every serious attacker now follows first, and why identity security posture management can no longer sit at the bottom of a security budget. Entra ID sits behind sign-in for enterprises, schools, health systems and government departments across an enormous share of the working world, which is exactly the scale that makes a single flaw at CVSS 10.0 a headline rather than a footnote, patched or not.
Why cloud identity security is the whole perimeter now#
For a decade, security teams built their defences around a network edge: firewalls, VPNs, a moat around a den of servers. That den has largely been abandoned. Work now happens through a browser, a token and a single sign-on prompt, and the only fence left standing is identity itself. The Hacker News's reporting on suspected Russian, Cozy Bear-linked activity, published 20 August 2026, describes attackers hijacking accounts by abusing Google OAuth consent flows and WhatsApp device-linking, bypassing multi-factor authentication not by breaking it but by walking through the front door it was told to trust. Defence, government and academic targets were named. None of it required a zero-day. All of it required identity security posture management that was watching the right signal at the right hour.
Put those three stories side by side and the range is the lesson. One flaw scored the maximum severity CVSS allows and hurt nobody, because it was caught first. A second, in Zimbra's collaboration suite, carries a real, ongoing exploitation problem serious enough that BleepingComputer's coverage of CISA's emergency directive gave federal agencies days, not months, to patch. A third needed no vulnerability whatsoever, just a login flow attackers could wear like a borrowed coat. Cloud identity security has to cover all three shapes of risk at once: the flaw that is caught, the flaw that is not, and the attack that never needed a flaw.
| Incident | Nature of the risk | Outcome so far |
|---|---|---|
| Entra ID, CVE-2026-69836 | Maximum-severity software flaw, CVSS 10.0 | Patched before exploitation, per Microsoft's advisory |
| Zimbra, CVE-2026-73570 | Actively exploited software flaw | CISA emergency directive, 12,000+ servers exposed |
| Google OAuth / WhatsApp abuse | Misuse of legitimate sign-in flows, no software flaw | Ongoing, suspected Cozy Bear-linked activity |

That is the practical brief now. A firewall still earns its keep, but the trail worth following, the scent worth reading before anything reaches the henhouse, runs through sign-ins, tokens and consent grants rather than open ports.
Why a compromised identity is usually ransomware's first step, not its last#
Ask most boards what identity threat protection are for, and they picture the moment files start encrypting. By then the story is nearly over. In the overwhelming majority of serious ransomware incidents, the first move was never the encryption, it was a stolen or abused identity: a token, a session, a set of credentials nobody flagged as unusual until the damage was already visible. Entra ID sitting at CVSS 10.0, even briefly, illustrates exactly why identity threat protection now have to start with identity, not backups.
NVD's own enrichment called the potential impact of CVE-2026-69836 ‘total’, the same word that describes what ransomware wants: complete control, not partial access. Confidentiality, integrity and availability all rated High in the same vector string that describes a textbook ransomware entry point. An attacker who reaches that level inside Entra ID does not need to find a second door; every other door in the building already answers to the one key they are holding.
That gap, 10.0 down to 8.7, is the whole story rendered as a single measurement: the danger that would have existed is not the danger that occurred, because someone closed the gap before the clock ran out. Vulnerability management solutions meet a 24-hour deadline covers a similar race against a different clock, and the pattern repeats: the flaws that make the calmest headlines are, almost always, the ones caught first.
None of this argues against identity threat protection that still assume encryption is the opening move. It argues for widening what those services watch. MDR Services Just Grew a Second Set of Watchful Eyes covers the same widening from a different angle: detection that watches identity signals as closely as it watches endpoints, because by the time a ransomware note appears, the identity door was propped open days, sometimes weeks, earlier.
What good identity security posture management actually watches#
In practice, identity security posture management means watching for the pattern a compromised identity leaves behind, not just the compromise itself: sign-ins from two continents an hour apart, a token replayed outside its expected window, a new OAuth consent grant nobody remembers approving, a service principal minted at 3am with permissions nobody assigned it, or a user suddenly approving MFA prompts they never requested because fatigue has worn the habit smooth. Entra ID logs nearly all of it. The question is whether anything is reading the log before the quarry has already slipped through the hedgerow.
Privileged access, and the questions every board should be asking now#
A maximum-severity identity flaw is also a reminder of where the next line of defence sits: privileged access management services that limit what any single compromised identity, human or machine, can actually reach once it is inside. Vendors are moving the same direction. Brinqa's own announcement, dated 19 August 2026, confirms its acquisition of PlexTrac to build what it calls a unified exposure-management platform, one more sign that the industry is buying validation capability rather than building it slowly in-house.
That consolidation sits inside a market that is not shrinking. SNS Insider's research, distributed via GlobeNewswire projects the third-party and exposure risk management market to reach $33.82 billion by 2035, pushed in part by regulatory pressure: the SEC's cyber disclosure rules, GDPR and the EU's NIS2 directive all now expect an organisation to show its identity and third-party exposure work, not simply claim it.
Microsoft's own patch record on CVE-2026-69836 is, in fairness, exactly the kind of evidence a regulator would want to see: found, fixed, disclosed with an honest severity score attached, no spin about exploitation that did not happen. Microsoft entra id security is genuinely strong on that measure. It is also, on its own, only one layer. The prowl of an APT29-linked actor abusing a trusted OAuth flow does not touch Entra ID's patch cadence at all, which is precisely why privileged access management services and independent monitoring still earn their budget line even on a platform that patches this well.
A platform that patches well is still one layer. Identity threat detection is the layer that watches every other door too.
Brush past the acquisition headlines and the underlying question is the same one Entra ID's near miss raises: who is watching the identity layer continuously, rather than reading the vendor's changelog once a quarter? Privileged access management services earn their keep precisely here, by treating every admin account, every service principal and every standing permission as a door that needs a named owner and a reason it is still propped open, rather than a setting configured once and forgotten.
Other vendors are hedging the same way from a different angle. LG Uplus's own launch of a global bug bounty programme with HackerOne, reported 24 August 2026, is the first time a South Korean telco has paid outside researchers to find its flaws before an attacker does, the identity-adjacent instinct at national-infrastructure scale.
Trust itself is the thing under test everywhere this month. The Hacker News's reporting on a reproducible context-injection attack against Grok, credited to researcher Rony Utevsky at Adversa AI, shows an AI assistant can be talked into leaking chat data the same way Entra ID's flaw would have accepted an unverified parcel: a different fence, the same instinct to trust an input too quickly. And the cost of getting identity security posture management wrong keeps climbing: GDPR fines reported via GlobeNewswire hit €225 million in Q2 2026 alone, a 230% jump on the previous quarter, a bracing number for any board weighing whether identity security posture management is worth the budget line.
What identity security posture management looks like on a quiet Tuesday, not just after an incident#
For every organisation Entra ID protects, this week was a lesson in patience rewarded. For every vendor selling into that same identity stack, whether the product is privileged access management services, identity threat protection, or an exposure-management platform, it was also a marketing test: could you explain a CVSS 10.0 flaw to a nervous prospect in the same week the story broke, accurately, without downplaying the severity or manufacturing a panic the facts do not support?
That is precisely the discipline folkfox's content marketing and SEO and GEO services are built around: turning a fast-moving, technical story into copy a compliance officer can forward to their board without wincing, and that a generative search summary can quote without distorting it. Brand strategy work for identity and access vendors increasingly means exactly this: being the source cited correctly the week a CVE breaks, not the vendor still drafting a statement three days after the news cycle has moved on.
The same discipline shows up in AI security testing and the jailbreak that went shopping for a weaker model, another story about a system trusting an input it should have interrogated first. Entra ID trusted a serialised parcel it should have inspected. A jailbroken model trusted a prompt it should have questioned. Identity threat detection, at its core, is the discipline of no longer extending that trust by default.
The fox that survives the season is not the one that never meets a threat, it is the one that reads the wind early enough to already be moving before the threat arrives. Entra ID's CVSS 10.0 flaw is, in the end, a story about exactly that kind of timing: patched, quiet, and closed before anything got to prowl through it. Outfoxing the next one is simply a matter of watching the gate as closely on an ordinary Tuesday as everyone suddenly watched Entra ID on the Thursday this CVE broke.
Frequently asked questions#
What is identity security posture management?
Identity threat detection is the continuous monitoring of sign-ins, tokens, consent grants and privileged accounts for signs of misuse, rather than relying only on a platform's own patches. Entra ID's CVE-2026-69836 shows why: the patch was fast, but no patch cadence covers stolen credentials or abused OAuth flows.
What is privileged access management?
Privileged access management is the set of controls that limit what an elevated account can do and see. Many organisations now buy privileged access management services rather than build the tooling alone, because continuous monitoring of admin and service accounts is specialist, always-on work an in-house team often struggles to staff.
Is Microsoft Entra ID security enough on its own?
Microsoft Entra ID security covers authentication and identity protection well, and this near miss shows Microsoft patching a maximum-severity flaw before it was ever used. But that is one layer, not the whole stack: independent monitoring, privileged access management services and incident response planning still matter regardless of how well the platform itself patches.
Was CVE-2026-69836 ever actually exploited?
No. Microsoft's own security advisory records ‘Exploited: No’ for CVE-2026-69836 and states the flaw is already fully mitigated, with no action required from users. The maximum CVSS score describes what the flaw could have done, not what it did.
Why is identity considered the new security perimeter?
Work now happens through browsers, tokens and single sign-on rather than a fixed office network, so the login itself has become the boundary attackers test first. Accounts hijacked this same week through legitimate Google OAuth and WhatsApp device-linking flows show why cloud identity security, not the firewall, is where defenders now concentrate.
How does a compromised identity lead to ransomware?
Most serious ransomware incidents begin with a stolen or misused identity long before any file is encrypted. That is why modern identity threat protection start by monitoring sign-ins, tokens and privileged accounts rather than waiting for encryption to give the attack away.
Read more on this topic#
MDR Services Just Grew a Second Set of Watchful Eyes
The same widening from endpoint to identity, told through an MDR acquisition.
Read the pieceAI security testing and the jailbreak that went shopping for a weaker model
Another system that trusted an input it should have interrogated first.
Read the pieceVulnerability management solutions meet a 24-hour deadline
A different clock, the same race between disclosure and exploitation.
Read the pieceReady to be the source cited the week the CVE breaks?
folkfox builds the marketing and positioning layer for identity, access and exposure-management vendors who want to explain a CVSS 10.0 story accurately and fast, not draft a statement three days late.