GetPentest

Microsoft patches a 10.0 in Entra ID

August 25, 2026. From issue 3 of The Compliance Brief, one story for teams that commission penetration tests.

Last reviewed 2026-08-25Written by Jacob Masse, TrazTech Inc.

Issue 3 of The Compliance Brief went to subscribers on August 25, 2026. One of its 5 stories bears on exploited vulnerabilities and security testing, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Help Net Security

Microsoft patched CVE-2026-69836, a remote code execution flaw in Entra ID carrying a CVSS score of 10.0, which was initially reported as exploited in the wild. Entra ID, formerly Azure Active Directory, handles logins and access to Microsoft 365, Azure and connected third-party applications.

Our take, in short

The patch is Microsoft's problem, but the questionnaire is yours. If your product federates with Entra or your own staff sign in through it, assume a buyer's security team asks this week whether you were affected, and have an answer that references sign-in logs and privileged service principals rather than a shrug.

Read the full take on traztech.ca

Also in issue 3

Outside exploited vulnerabilities and security testing, but in the same email:

Older: issue 1 All issues on GetPentest Newer: issue 4