Entra ID flaw was exploited, advisory names no indicators
Microsoft confirmed a maximum-severity Entra ID flaw was exploited before it was fixed, then published an advisory with no indicators defenders could use.
Today's ledger carries four security stories. What separates them is not severity. It is whether a defender who read them could do anything afterwards.
Identity failed in three places
Microsoft confirmed that CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that let an unauthorized attacker execute code over a network without privileges, was exploited in attacks before the company mitigated it in its own cloud infrastructure. The advisory names no targets, no exploitation window, and no indicators anyone could check their logs against, per BleepingComputer.
Alation, the data and AI cataloguing company, confirmed a cyberattack and an open investigation without saying how the attackers got in, whether customer data, credentials or connected systems were reached, or how many customers are affected, according to eSecurity Planet. U.S. Bancorp said the data a ransomware gang claims to have stolen came from a breach at a contractor to one of its third-party suppliers and does not touch its own systems, The Record reported.
Three confirmations, three investigations, and nothing a defender can run.
The fourth one ends in a version number
Oblique Security researchers running Anthropic's Claude in a vulnerability research pipeline found XML signature verification bypasses in SAML implementations that amount to full authentication bypasses in four projects. One of them, the open-source identity provider Authentik, fixed the flaw in versions 2026.2.6 and 2026.5.5, Cybersecurity News reported.
That is the same class of failure as the Entra ID flaw: authentication bypassed at the identity layer. It is the only one of today's four that a team can act on tonight, and it did not come out of a disclosure process. It came out of a pipeline pointed at source code, which is now the cheap half of the problem. Writing the advisory is the expensive half, and it has not moved.
The layer everyone is loading up
Salesforce spent the same week expanding Headless 360 across every major cloud with new Model Context Protocol servers, Data 360 capabilities, Slack integrations, developer tools and reusable Skills, so that authorized AI agents act through the identity, permissions, metadata and governance an organisation already established in Salesforce rather than through a separate agent stack, Tech in Asia reported.
That is the industry's answer to agent access control, and it is a reasonable one: reuse the permission system that already exists instead of inventing a second one nobody audits. It also means the identity layer now carries the blast radius of every agent an organisation runs. Anthropic shipped Claude Sonnet 5 in June built to plan, drive browsers and terminals, and run autonomously. Every one of those sessions authenticates as somebody.
What today actually leaves you
- Patch Authentik to 2026.2.6 or 2026.5.5.
- For Entra ID, take Microsoft's word that its cloud is mitigated, because the advisory gives you no way to check whether you were hit.
- For Alation and U.S. Bancorp, wait for an investigation to name a scope.
The gap between those two states is the story. Finding an authentication bypass now scales with compute. Telling the people who run the software what to look for still scales with whoever writes the advisory, and three times out of four today, they wrote nothing a defender could use.
Built from the digest of 2026-08-22.