https://reddit.com/r/sysadmin/comments/1vwibli/microsoft_dropped_a_cvss_100_entra_id_rce_said_it/: Microsoft dropped a CVSS 10.0 Entra ID RCE, said it was exploited, then walked that back a day later. No customer patch.
Published Aug 23, 2026
·Updated
Affected Software
1 affected component
Microsoft Entra ID
Frequently Asked Questions
1
Do customers need to apply a patch or configuration change?
No customer patch is identified in the available information. Microsoft stated that the issue was already fixed on its side.
2
Should this be treated as confirmed active exploitation?
The initial advisory reportedly marked the issue as exploited in the wild, but that indication was removed the following day. Based on the available information, active exploitation is not confirmed.