The Entra ID flaw earned the highest possible severity score, but Microsoft says it patched the bug before publishing the CVE and found no evidence it was ever exploited.
Source: [Decrypt](https://decrypt.co/376287/microsoft-perfect-10-exploit-hackers-run-code)