Microsoft's advisory said the CVSS 10 was exploited — by evening it said it was not, and the headlines had already gone
2026-08-21Security
CVE-2026-69836 is a real maximum-severity flaw in Entra ID, and Microsoft fixed it cloud-side with nothing for customers to do. For most of 21 August its own bulletin marked it exploited in the wild. Microsoft corrected that field to No after a reporter asked. The correction has not travelled the way the original did.