Known Vulnerabilities for Dynamics 365 by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Dynamics 365" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-66301 json | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attac... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-65815 json | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over ... | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-55944 json | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-07-14 | 2026-07-22 |
| CVE-2026-47647 json | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-06-18 | 2026-06-24 |
| CVE-2026-47646 json | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an... | Not Provided | 2026-07-09 | 2026-07-09 |
| CVE-2026-42898 json | Not Provided | 2026-05-12 | 2026-05-14 | |
| CVE-2026-42833 json | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attack... | Not Provided | 2026-05-12 | 2026-06-01 |
| CVE-2026-40417 json | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | Not Provided | 2026-05-12 | 2026-08-10 |
| CVE-2026-40375 json | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | Not Provided | 2026-08-11 | 2026-08-12 |
| CVE-2026-40371 json | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized atta... | Not Provided | 2026-06-09 | 2026-07-15 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Dynamics 365 | 9.0.9.4 | |||
| Application | Microsoft | Dynamics 365 | 9.0.8.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.7.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0.6.9 | |||
| Application | Microsoft | Dynamics 365 | 9.0.5.5 | |||
| Application | Microsoft | Dynamics 365 | 9.0.4.0005 | |||
| Application | Microsoft | Dynamics 365 | 9.0.3.7 | |||
| Application | Microsoft | Dynamics 365 | 9.0 | |||
| Application | Microsoft | Dynamics 365 | 8.2 | |||
| Application | Microsoft | Dynamics 365 | 7.0 | |||
| Application | Microsoft | Dynamics 365 | 10.0.11 | |||
| Application | Microsoft | Dynamics 365 | - | |||
| Application | Microsoft | Dynamics 365 | - |