Known Vulnerabilities for Dynamics 365 by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Dynamics 365" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77908 json | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute ... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-66301 json | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attac... | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-65815 json | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over ... | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-65772 json | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-55944 json | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-47647 json | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-06-18 | 2026-06-24 |
| CVE-2026-47646 json | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-42898 json | Not Provided | 2026-05-12 | 2026-05-14 | |
| CVE-2026-42833 json | Not Provided | 2026-05-12 | 2026-06-01 | |
| CVE-2026-40417 json | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-08-10 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Dynamics 365 | 9.0.9.4 | |||
| Application | Microsoft | Dynamics 365 | 9.0.8.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.7.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0.6.9 | |||
| Application | Microsoft | Dynamics 365 | 9.0.5.5 | |||
| Application | Microsoft | Dynamics 365 | 9.0.4.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.3.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0 | |||
| Application | Microsoft | Dynamics 365 | 8.2 | |||
| Application | Microsoft | Dynamics 365 | 7.0 | |||
| Application | Microsoft | Dynamics 365 | 10.0.11 | |||
| Application | Microsoft | Dynamics 365 | - | |||
| Application | Microsoft | Dynamics 365 | - |