webinar | English

CVSS 10.0 in Entra ID:
What Microsoft’s Patch Doesn’t Fix

And where security risks still lurk

DATE/TIME

Tuesday, October 6, 2026 at 11:00 AM EST I 4 PM BST I 5 PM CEST | 30 Minutes I Zoom

In August 2026, a critical vulnerability in Entra ID (CVE-2026-69836), rated a perfect CVSS 10.0, caused quite a stir. This incident demonstrated once again just how exposed central identity systems can be. The patch has been released, and the issue has been resolved at the code level. But this is precisely where the real question, the focus of this webinar, begins: what remains once the patch has long since been applied?

In 30 minutes we’ll discuss:

  • How over-permissioning and delegation chains have evolved over time, and access rights that no one tracks can still pose serious security risks, even after a critical patch
  • Where these threats typically hide, in Active Directory and Entra ID
  • How a comprehensive view across your environment can provide clarity and close security gaps

We look forward to your participation!

PRESENTER

Author headshot

Jeffrey Melnick

Director of Solutions Engineering, S&C

Please note: When you register for the webinar, you'll receive the login information directly from Zoom.