Microsoft has confirmed active exploitation of a maximum-severity, CVSS 10.0 remote code execution flaw in Entra ID, its cloud identity platform underpinning countless UK hybrid-work estates. The bug is already fully mitigated by Microsoft, but the episode is a fresh reminder of how much trust organisations place in a single identity provider.
View the data behind this chart
| Critical Threshold | This Entra ID Flaw | Maximum Possible | |
|---|---|---|---|
| CVSS Score | CVSS9 | CVSS10 | CVSS10 |
What Microsoft disclosed on 20 August 2026
Microsoft warned on Thursday, 20 August 2026, that a maximum-severity vulnerability in Entra ID had been exploited in the wild. Tracked as CVE-2026-69836 with a CVSS score of 10.0, the flaw stems from deserialization of untrusted data in the cloud identity service, allowing an unauthorised attacker to execute code over a network without any user interaction.
Microsoft's own description, as reported, is blunt: "Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network." The company also stated the vulnerability "has already been fully mitigated by Microsoft," and that "there is no action for users of this service to take."
Why a CVSS 10.0 identity flaw is different
A 10.0 score is the ceiling of the CVSS scale, reserved for flaws that are trivially exploitable over a network, require no privileges or user interaction, and carry total impact on confidentiality, integrity and availability. Entra ID is not a peripheral system; it is the authentication backbone for Microsoft 365, Azure and countless third-party SaaS integrations that UK organisations run their hybrid workforces on. A remote code execution bug in that layer, rather than in a single application, has a blast radius that touches identity, access and every downstream service trusting that identity.
This is precisely why organisations building Zero Trust architectures treat identity providers as a critical control plane, not just another cloud service to bolt on.
Current status: mitigated, but questions remain
As of today, the status is resolved rather than in progress: Microsoft says the flaw has already been fully mitigated and customers are not required to take any action. That is a meaningfully different position from a typical Patch Tuesday advisory where organisations must schedule and verify their own remediation.
However, the reporting reviewed here does not disclose how the vulnerability was exploited, when exploitation began, or whether it is still ongoing. There is also no independent confirmation of attacker identity, scope, or the exact mechanics of the attack. For UK buyers, that gap matters: a server-side fix closes the vulnerability going forward, but it does not retroactively tell you whether your tenant was among those targeted before mitigation landed.

What UK IT buyers should check now
Even with Microsoft's server-side fix in place, hybrid-work organisations relying on Entra ID should not treat this as a closed matter. Practical steps worth prioritising include reviewing Entra sign-in and audit logs around the disclosure window for anomalies, confirming conditional access and privileged role assignments have not changed unexpectedly, and validating that break-glass accounts and admin session policies are intact.
Because the underlying flaw sat in a cloud service outside customer control, this is also a good moment to pressure-test your own layered defences rather than relying solely on the identity provider's patching cadence. Teams without dedicated capacity for this kind of log review and exposure check should consider bringing in vulnerability management services or extending existing managed detection & response coverage to include identity telemetry specifically.
- •Review Entra ID sign-in and audit logs around 19–21 August 2026 for anomalies
- •Reconfirm privileged role assignments and conditional access policies
- •Test break-glass account integrity and session revocation procedures
- •Extend detection coverage to identity-layer telemetry, not just endpoints
The bigger picture for hybrid-work identity risk
Organisations that have moved identity into the cloud gain resilience against on-premises compromise, but they also concentrate risk in a vendor's infrastructure they cannot directly patch or inspect. This incident, alongside prior Entra ID advisories, underlines why buyers evaluating identity strategy need to understand Microsoft Entra ID risk profiles alongside its convenience benefits, and why secure your cloud environment reviews should explicitly include identity-provider dependency mapping.
For most UK organisations the practical answer is not to abandon cloud identity, but to pair it with independent monitoring, tested incident response playbooks and a clear-eyed view of what "fully mitigated by the vendor" does and doesn't cover. Firms without in-house capacity for that should speak to specialists offering comprehensive cybersecurity strategies built around this exact dependency.
- 01BleepingComputer — Microsoft Entra ID flaw CVSS 10.0 exploited in wild allows remote code execution · 21 August 2026
- 02The Hacker News — Microsoft Entra ID Flaw CVSS 10.0 · 21 August 2026
