Microsoft Patches Severe Entra ID Flaw CVSS 100 Allowing Remote Code Execution

Update The story was updated after publication to note that the vulnerability has not been exploited Although the security bulletin originally marked the Exploited field under the Exploitability Assessment table as Yes on August 21 2026 Microsoft corrected the Exploited status to No after The Hacker News contacted the company for comment It also noted this vulnerability was not