Microsoft Retracted the Entra ID Exploitation Claim. CISA Still Lists the CVE as Known Exploited.

Update, 22 August 2026: Microsoft has told BleepingComputer that it mistakenly marked a maximum-severity Microsoft Entra ID vulnerability as exploited in the wild. The correction removes the strongest public claim behind the first version of this article. It does not…








