08/29/2026
A CVSS 10.0 Microsoft Entra ID flaw was briefly reported as "actively exploited" this week. A day later, Microsoft corrected that, confirming it wasn't.
The bug itself was real, and Microsoft fixed it before going public. But the exploitation claim turned out to be an error in the advisory, not an actual attack.
A good reminder that a scary severity score and a confirmed attack aren't the same thing, worth checking which one you're actually looking at before reacting.