Skip to main content

folkfox

Skip to main content
Skip to content
CYBERSECURITY

A Perfect Ten, and the Word Microsoft Took Back

Microsoft's identity platform earned the highest severity score the scoring system allows, then Microsoft quietly walked back the scariest word in its own bulletin. For anyone whose job is selling security credibility, the retraction is the real story, not the flaw.

Quick answerA vulnerability disclosure policy is only as good as its correction speed. Microsoft's CVSS 10.0 Entra ID flaw was first marked exploited, then wasn't, patched cloud-side with nothing for customers to do.
Section 01

What actually happened on 20 and 21 August#

A fox does not panic at every snapped twig in the hedgerow. It freezes, reads the wind, and works out whether the sound was a predator or a fallen branch. Most of the internet skipped that second step this week, and the story of why is really a story about vulnerability disclosure policy.

On 20 August 2026, Microsoft disclosed CVE-2026-69836, a flaw in Entra ID, the identity and access management platform formerly called Azure Active Directory that decides who gets into what across Microsoft 365, Azure and a very long tail of connected apps. This was a remote code execution vulnerability of the deserialization kind, catalogued by MITRE as CWE-502, the bug class where a server trusts a malicious blob enough to run it as code. The National Vulnerability Database's own scoring puts it at a full 10.0, the ceiling of the Common Vulnerability Scoring System: network-reachable, low complexity, no privileges and no user interaction required, the worst possible reading on every axis that matters.

That score alone would have earned a scary headline on its own scent. What actually spread the story was one field in Microsoft's own bulletin, the one a sound vulnerability disclosure policy is supposed to govern tightly: Exploited. It initially read Yes.

The one-word correction nobody advertised#

According to The Hacker News, Microsoft's advisory "initially marked the 'Exploited' field as 'Yes'", and corrected it to "No" on 21 August, a single day later, after the outlet contacted the company for comment.

Microsoft's own words, as quoted by that report: "this vulnerability was not exploited in the wild." A company spokesperson added the mitigation line that mattered most to defenders: "We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency. There are no additional actions customers need to take."

Where 10.0 sits on the scale that scores it
Bar chart of the four CVSS 3.1 severity bands by their upper bound, with Entra ID's flaw noted at the top of the Critical bandLow (top): 3.9Medium (top): 6.9High (top): 8.9Critical: Entra ID: 10107.552.503.9Low (top)6.9Medium (top)8.9High (top)10Critical: Entra ID
The Common Vulnerability Scoring System caps at 10.0. Entra ID's flaw did not land near the critical threshold, it sat on the ceiling of the entire scale.

Sit with that timeline for a second. A maximum-severity score, a claim of active exploitation, a wave of coverage built on that claim, and a correction that landed roughly twenty-four hours later, prompted by a single reporter's question rather than a proactive update under Microsoft's own vulnerability disclosure policy. Most of the trade press had already filed by then.

Most of the sharing on Help Net Security and elsewhere carried the scarier version forward, because a correction rarely travels as fast as the alarm it corrects, and no vulnerability disclosure policy on earth can outrun a headline once it has left the den.

Section 02

Why the vulnerability disclosure policy matters more than the flaw#

Here is the uncomfortable part for anyone in security marketing, vCISO advisory or GRC reporting. The remote code execution vulnerability itself required almost nothing of you.

Entra ID is a fully managed cloud service, so Microsoft patched its own infrastructure and there was no update to roll out, no configuration to change, nothing to test on a Friday afternoon. The retraction is the part that actually touches your job, because it is a live example of a vendor's severity language moving under a reader's feet, and it is exactly what a vulnerability disclosure policy exists to govern.

A vulnerability disclosure policy sets out what a vendor commits to say, when, and how a correction gets issued once new facts arrive. Microsoft's own vulnerability disclosure policy worked in the narrow sense that the record was fixed within a day. It worked less well in the broad sense that the correction was reactive, not proactive, triggered by a journalist rather than a scheduled review, and it never travelled with the same force as the original claim.

Exploited: Yes

Coverage ran hot within hours. A maximum-severity flaw in the identity backbone of Microsoft 365, reportedly already under attack, is precisely the kind of headline that gets forwarded before it gets read closely.

Exploited: No

"This vulnerability was not exploited in the wild," per Microsoft's own correction to The Hacker News. The fix was already live. The correction had to compete with a day-old headline for the same attention.

The lesson is not that Microsoft lied. Vulnerability triage under pressure is genuinely hard, and a same-day correction is faster than most vendors manage under their own vulnerability disclosure policy, if they have a written one at all. The lesson is that a claim about exploitation status is working data, not a settled fact, right up until a second, sceptical source has had a chance to check it.

Security marketers who repeat the first number they see, instead of the corrected one, are laundering someone else's mistake into their own credibility. That is exactly the discipline folkfox brings to content marketing for security and compliance clients: cite the primary source, date the claim, and update the piece the moment the vendor does, rather than let a retracted number sit on a page collecting search traffic under false pretences.

Section 03

The identity and access management market doesn't get to be sloppy either#

Entra ID is identity and access management infrastructure at genuine planet scale, and this remote code execution vulnerability sits squarely inside a category that has grown fast precisely because identity, not the network edge, is where attention has shifted.

That growth has a side effect worth naming plainly. A crowded, well-funded corner of identity and access management attracts vendors who reach for the scariest available framing, because fear converts. A retracted "exploited in the wild" claim from a company as large and as scrutinised as Microsoft is a useful reminder of how easily an unverified severity label becomes marketing copy, and how much damage it does to a smaller vendor's credibility once a customer notices the gap between the claim and the correction.

How close to the ceiling a 10.0 actually sits
How close to the ceiling a 10.0 actually sitsBullet chart showing a CVSS value of 10.0 against a critical-severity target of 9.0CVE-2026-69836: 10 of 9CVE-2026-6983610
A CVSS score of 10.0 clears the Critical threshold (9.0) by a full point, the maximum headroom the scale allows. There was no higher number available to report.

This is where cloud identity security earns its keep for reasons that have nothing to do with this particular flaw. Microsoft's own guidance was, correctly, that customers of the managed service had nothing to patch. But "nothing to patch" is not the same claim as "nothing to check".

A tenant that was already compromised through some other route would not be un-compromised by Microsoft's server-side fix. Cloud identity security tooling exists precisely to answer the question a vendor's own advisory cannot: did anything unusual happen in your environment in the window before the fix landed. OWASP's own guidance on this bug class, software and data integrity failures, is blunt about it: deserialization flaws are attractive precisely because they let an attacker skip straight past the front gate rather than picking the lock.

Section 04

What a credible vendor says instead#

None of this is an argument for under-reacting to real severity. A 10.0 is a 10.0, and the fox that never checks the hedgerow gets eaten eventually too. It is an argument for a narrower, more disciplined kind of urgency, one that survives a correction instead of being embarrassed by it, which is what a genuinely good vulnerability disclosure policy is built to deliver.

Five moves before you repeat a severity claim
Read the vendor's own wording

Not the aggregator's headline. Microsoft's exact correction, quoted directly, said far more precisely what changed than any summary of it.

Separate 'patched' from 'checked'

A cloud-side fix closes the door. It does not tell you whether anything walked through it first. Say both, not just the reassuring half.

Date every severity claim

An exploitation status from hour one of a disclosure is not the same fact as the status twenty-four hours later. Timestamp the version you are citing.

Update the correction as loudly as the alarm

A retraction buried in an edit log does not undo the reach of the original headline. Republish, do not just amend.

Check your own tenant regardless

Review admin role assignments, new app registrations and credential changes for the disclosure window, whatever the vendor's advisory says about customer action.

Section 05

Measuring trust after the correction#

The retraction did not stop the story travelling. Screenshots of the original "exploited in the wild" framing were still circulating on social platforms days after Microsoft's correction landed, exactly the half-life problem every security vendor and every marketing team attached to one needs to plan for.

@mwyr.es
Microsoft Entra ID Flaw (CVSS 10.0) Exploited In Wild, Allows Remote Code Execution
23 August 2026View on X

That post, shared two full days after Microsoft's own correction, still carried the pre-retraction framing, sourced back to the original Hacker News headline before its edit. It is not evidence of bad faith. It is evidence that a correction has to out-compete the original claim on every channel it appeared on, not just the one where it was issued, or the scarier version simply keeps being true in the corners of the internet the correction never reached.

A vendor's first severity claim is a working hypothesis. Treat it like one, and the correction never costs you anything.
folkfox, on reporting vulnerability disclosure policy honestly

None of this is unique to Entra ID, or to Microsoft. Zero day disclosure practice across the whole industry runs on the same fault line, a first, urgent claim that outruns the slower, more careful correction behind it, every single time a scent this strong hits the trail. CISA's own Known Exploited Vulnerabilities catalogue exists for exactly this reason, a single, dated record of what is confirmed, not claimed, to be under active attack.

For a marketing or compliance team building credibility in identity and access management, cloud identity security, or any adjacent buyer-intent category, the practical takeaway is dull on purpose: cite the dated, corrected version of a claim, say plainly when a number changed and why, and resist the urge to keep the scarier framing live because it performs better in a feed.

That discipline is also, not coincidentally, exactly what makes a page safe for a generative answer engine to quote, because a claim that survives its own correction is a claim worth repeating. It is the same standard folkfox holds its own SEO and GEO work to, and the same one we apply when we build out a client's brand strategy around genuinely defensible claims rather than the first draft of a headline.

If your last written vulnerability disclosure policy predates the first time your marketing team had to walk a claim back in public, this is a good week to revisit it. If you want that discipline built into your reporting and content from the start, that is what folkfox does.

Questions

Frequently asked questions#

What is CVE-2026-69836?

It is a maximum-severity remote code execution vulnerability in Microsoft Entra ID, the identity and access management platform behind Microsoft 365 and Azure sign-in. Scored 10.0 on CVSS 3.1, it stemmed from deserialization of untrusted data. Microsoft fixed it on its own cloud infrastructure on 20 August 2026.

Was the Microsoft Entra ID flaw actually exploited in the wild?

Microsoft's advisory initially said yes, then corrected that field to "No" on 21 August 2026, a day after disclosure, telling The Hacker News the vulnerability was not exploited in the wild. Treat the corrected status as the accurate one.

Do I need to patch anything for CVE-2026-69836?

No. Entra ID is a fully managed cloud service, so Microsoft applied the fix to its own infrastructure. There is no customer-side patch, update or configuration change required, per Microsoft's own statement.

What should a vulnerability disclosure policy actually cover?

A vulnerability disclosure policy should state when a vendor commits to publish severity information, how quickly it updates a field like exploitation status once new facts arrive, and how loudly it republishes a correction relative to the original alarm. Microsoft's delivered a same-day fix to the record, but only after a journalist asked.

What is the difference between identity and access management and cloud identity security?

Identity and access management is the broader discipline of controlling who can access what, covering sign-in, roles and permissions. Cloud identity security is the narrower practice of monitoring that identity layer for misuse, compromised accounts, rogue app registrations, unusual credential changes, once access management is already in place.

How common is a zero day disclosure correction like this one?

No reliable public figure exists for how often an initial 'exploited in the wild' claim gets walked back, so treat this case on its own facts rather than as proof of a wider pattern. What is measurable is the timeline: disclosure and correction landed one day apart.

Keep reading

Read more on this topic#

Ready for security content that survives its own correction?

folkfox builds content and reporting for security and compliance vendors that cites the dated, primary source and updates the moment the vendor does, the same discipline that keeps a claim safe to quote.