Microsoft fixed a max-severity Entra ID flaw in its cloud, so there is no customer patch for CVE-2026-69836
Microsoft published CVE-2026-69836, a CVSS 10.0 deserialization RCE in Entra ID, its cloud identity service, and says it is already fully mitigated server-side with no action for customers. There is no patch to apply, and Microsoft flipped the advisory's exploitation label from active to none on Friday without explaining the change.

Microsoft published CVE-2026-69836 on August 20, a maximum-severity remote code execution flaw in Microsoft Entra ID, the company's cloud identity and access management service, formerly Azure Active Directory. The advisory rates it CVSS v3.1 10.0, the top of the scale. In Microsoft's own words, "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network." The detail that reframes the whole alert sits in the same advisory: "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take." BleepingComputer, Help Net Security and Cybersecurity Dive all reported it from Microsoft's MSRC advisory.
The instrument: a cloud-service CVE, not a box you patch
Read what the CVE is attached to. This is CWE-502, deserialization of untrusted data, in Entra ID, Microsoft's hosted cloud IAM. It is not on-premises Active Directory Domain Services, and it is not a Windows update you download and install. Microsoft credits the find to its own Robert Fitzpatrick, a principal security engineer, which fits a bug reported and closed inside the service rather than one handed to customers to remediate. The fix already shipped on Microsoft's side, which is why the advisory tells customers there is nothing to do.
Why it scores a perfect 10.0, and why that is not a 9.8 you patch
The vector is AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Read it left to right: reachable over the network (AV:N), low attack complexity, no privileges and no user interaction required, and full confidentiality, integrity and availability impact. The character that pushes it past the usual 9.8 network RCE is S:C, Scope Changed: the vulnerable component and the impacted component are not the same, so a compromise reaches beyond its initial boundary. Scope Changed is the reason the base score lands at a clean 10.0 rather than 9.8. It is a statement about blast radius inside Microsoft's identity plane, not a measure of how many of your servers need the update, because none of them do.
The exploitation label that flipped
Here is the live part of the story. Cybersecurity Dive reports that Microsoft's bulletin originally said the flaw was under exploitation, then updated the announcement on Friday to say there was no exploitation, and that the company "did not provide an immediate explanation for the status change." Coverage caught both states: BleepingComputer, working from the earlier bulletin, described a flaw "exploited in attacks," while the walked-back advisory now carries the opposite flag. Alongside that reversal, exploit code is not public (BleepingComputer notes it is "not yet available online"), Microsoft has named no threat actor, no start date and no victim count, and the CVE is not in the CISA Known Exploited Vulnerabilities catalog as of this cycle. What exists is a severity rating and a reversed exploitation flag, not a published incident report.
What this is not
Because the score is a 10.0, the reflex is to treat it like the last critical network RCE and start patching. There is nothing to patch. The vulnerable code runs in Microsoft's hosted Entra service, not in your tenant, and Microsoft has already mitigated it server-side. There is no customer-applied update, no exposed-appliance count to chase, and no reason to open a maintenance window. The "thousands of exposed instances" framing that fits an internet-facing appliance does not map onto a cloud IAM flaw the vendor fixed on its own infrastructure. If you administer Entra ID, this is closer to a status change on a dashboard you do not run than a task on your plate. It is a reminder that in a cloud identity service the risk sits on the provider's side of the line, a boundary that looked different when Fortune 500 tenants were hit in an Azure data-theft campaign, a separate incident where the exposure lived in customer configuration rather than Microsoft's own code.
The takeaway
Treat CVE-2026-69836 as what the advisory says it is: a cloud-service vulnerability Microsoft has already fully mitigated, with no action for customers. Do not open a customer patch window, and do not inventory appliances as if this were a NetScaler box you own. The one thing worth tracking is the reversal itself. Microsoft flipped the exploitation label from active to none on Friday without saying why, so if you run Entra ID, watch for a follow-up from Microsoft on that flag rather than for a patch that is never going to ship.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free