Update: The story was updated after publication to note that the vulnerability has not been exploited.
Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not
Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/microsoft-entra-id-flaw-cvss-100.html