CYBER DESK · HONG KONG · WEEKLY

Microsoft's 'No Action Needed' Leaves Banks Guessing

Microsoft patched a maximum-severity Entra ID flaw exploited in the wild and told customers no action was needed, but gave regulated institutions no way to verify they weren't compromised.
KT

The Disclosure That Wasn't

Microsoft disclosed CVE-2026-69836 on August 21, a deserialization flaw in Entra ID, the identity service that handles sign-in for Microsoft 365, Azure, and every enterprise app chained to them. The vulnerability scored a perfect 10.0 on the CVSS scale, the ceiling reserved for bugs that require no authentication, no user interaction, and no local access to achieve remote code execution. Microsoft's advisory states the flaw was reportedly exploited in the wild before the company mitigated it server-side. No customer patch exists, and Microsoft says none is needed.

That is also the entire disclosure. Microsoft named no attacker. It gave no exploitation window; not a start date, not an end date. It counted no affected tenants, not a number, not a percentage, not a 'small number of customers' hedge. Robert Fitzpatrick, the Microsoft principal security engineer credited with the report, gets a byline; the incident he is describing does not get a timeline. For a bank running its identity plane on Entra ID, as most APAC financial institutions do, the advisory answers whether the hole is closed. It does not answer whether anyone climbed through it while it was open.

Concentration Risk, Untested

MAS's Third-Party Risk Management guidelines and HKMA's cyber resilience framework are both built around the same fear: that one vendor's failure cascades through every bank, insurer, and broker plugged into it. HKMA's May 29 circular describes a Cyber Resilience Testing Framework, still in pilot, aimed at selected institutions by late 2026. CVE-2026-69836 is the scenario those frameworks exist to catch, arriving before the testing regime built to catch it is running.

No Hong Kong or Singapore bank running Microsoft 365 or Azure could have patched this on its own; the fix lived entirely on Microsoft's servers. None could have detected exploitation independently, because Entra ID's authentication logs are Microsoft's to hold, not the tenant's to inspect. And none can now attest, with evidence, that they were not among whichever number of tenants Microsoft has declined to disclose. This desk argued three weeks ago that Hong Kong's AI cyber rules assume a vendor to call. Here the vendor answered the phone, fixed its own house, and left the tenants downstream to write 'not applicable' on a form they cannot actually complete.

HKMA's pilot testing framework will eventually ask a bank to demonstrate it was not compromised by a vendor flaw it never saw the details of. Microsoft's advisory gives that bank nothing to demonstrate with, only a CVSS score and an assurance. The next Entra ID bug scoring 10.0, and there will be one, given last September's CVE-2025-55241, the prior Entra ID flaw that also hit maximum severity, will arrive with the same disclosure shape. The open question is whether any regulator writes a rule requiring Microsoft to answer, or whether attestation stays theatre.

Sources

PREVIOUS COLUMNS, CYBER INTEL DESK
The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.