Known Vulnerabilities for Dynamics 365 by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Dynamics 365" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42898 json | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attack... | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-42833 json | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attack... | Not Provided | 2026-05-12 | 2026-06-01 |
| CVE-2026-40417 json | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-05-13 |
| CVE-2026-33821 json | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges... | Not Provided | 2026-05-12 | 2026-05-15 |
| CVE-2026-33103 json | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally... | Not Provided | 2026-04-14 | 2026-04-27 |
| CVE-2026-32210 json | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing ove... | Not Provided | 2026-04-23 | 2026-04-30 |
| CVE-2025-47454 json | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Dynamics CRM gf-dynamics-crm ... | Not Provided | 2025-05-07 | 2026-04-23 |
| CVE-2025-32511 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Excellent Dynamics Make... | Not Provided | 2025-04-17 | 2026-04-23 |
| CVE-2025-24708 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks WP Dynamics C... | Not Provided | 2025-01-27 | 2026-04-23 |
| CVE-2024-34550 json | Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects Dynami... | Not Provided | 2024-05-14 | 2026-04-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Dynamics 365 | 9.0.9.4 | |||
| Application | Microsoft | Dynamics 365 | 9.0.8.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.7.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0.6.9 | |||
| Application | Microsoft | Dynamics 365 | 9.0.5.5 | |||
| Application | Microsoft | Dynamics 365 | 9.0.4.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.3.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0 | |||
| Application | Microsoft | Dynamics 365 | 8.2 | |||
| Application | Microsoft | Dynamics 365 | 7.0 | |||
| Application | Microsoft | Dynamics 365 | 10.0.11 | |||
| Application | Microsoft | Dynamics 365 | - | |||
| Application | Microsoft | Dynamics 365 | - |