On 21 August 2026, Microsoft disclosed and fixed a maximum severity flaw in Entra ID, the sign in system behind Microsoft 365, Azure, and a long list of other tools that use a Microsoft login. It scored 10.0, the highest severity rating that exists, and it needed no password and no action from a user to be used against a business.
Microsoft’s advisory first said the flaw had been used by an attacker before the fix went out. That turned out to be wrong. After being asked directly by a security news outlet, Microsoft corrected the entry and confirmed the flaw had not been exploited. The fix was already in place either way, and no business needed to do anything to be protected.
So the short version is good news. A very serious flaw was found and closed before it caused any harm.
Why it is still worth ten minutes of attention
The interesting part is not the flaw itself. It is what the whole episode shows about how much trust smaller businesses place in Microsoft, often without realising it.
Entra ID sits underneath almost everything. Every login to Microsoft 365, every connection to Azure, every other app that lets you sign in with Microsoft, all of it runs through Entra. This particular flaw needed no sign in and no action from a user, so it would not be expected to show as a normal login event even if it had been used. If an attacker had used it to do something afterwards, changing admin roles or registering a new app, that is the kind of thing a business’s own logs could pick up. But whether the flaw was used in the first place is not something a business could ever check for itself.
The only account of whether it had been exploited came from Microsoft. That account changed within a day of being published.
Larger organisations tend to have a security team who would have noticed the advisory change from Yes to No. They would have asked questions and formed their own view. Most smaller businesses, especially those running on a lean or fully outsourced IT setup, will only ever see the first version of the story, if they see it at all.
That is not a criticism. Depending on a major platform vendor to get security right is a completely reasonable choice for a smaller business, since building that expertise in house rarely makes sense. But it does mean the trust is total. There is no second opinion available.
What to actually do about it
Nothing here requires a security team or specialist tools. Three things are worth ten minutes each.
- Check who has admin rights in your Microsoft 365 or Azure setup, and whether all of them still need it. Admin accounts are the ones worth the most to an attacker, and they are also the ones that quietly accumulate people who left a role, or a project, months ago.
- Confirm multi factor authentication is switched on for every account, not just the ones you remember setting it up for. New accounts and old ones can slip through this without anyone noticing.
- If you use conditional access policies to control who can sign in from where, take five minutes to check they still reflect how your business actually works. Policies set up a year or two ago often lag behind how the team has changed since.
None of this is specific to this particular flaw. That is the point. When something like this happens and turns out fine, the useful response is not to panic about one CVE. It is to use the moment as a nudge to check the basics are still in good shape, since those are the things actually within your control.
The bigger point
A platform vendor catching and fixing a serious flaw before it does damage is Microsoft’s system working as intended. It is a good outcome. But it is worth noticing how little visibility a smaller business has into that process, and how much of the story is simply taken on trust.
That is not a reason to worry about Microsoft 365 specifically. It is a reason to keep the basics, admin access, multi factor authentication and conditional access, in good order as a standing habit, so that the one thing within your control is never the weak point.
Sources: Help Net Security and The Hacker News, both reporting on CVE-2026-69836, August 2026.
Not certain who still has admin rights in your Microsoft 365. Talk to an expert.