CVE-2026-65815
8.8Microsoft · Dynamics 365 (on-premises)
A deserialization of untrusted data flaw in Microsoft Dynamics 365 (on-premises) enables an authenticated attacker to execute arbitrary code over a network.
Executive summary
Microsoft Dynamics 365 (on-premises) is vulnerable to a high severity deserialization flaw that could lead to remote code execution.
Vulnerability
This vulnerability involves CWE-502, Deserialization of Untrusted Data, allowing an attacker with low-level authenticated access to achieve remote code execution.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting the high potential for system-wide impact. If exploited, an attacker could compromise sensitive business data stored within the Dynamics 365 environment or gain a foothold to further attack the internal network.
Remediation
Immediate Action: Update your on-premises Dynamics 365 installation to version 9.1.0047.0006 or later immediately.
Proactive Monitoring: Review system and application logs for anomalous deserialization errors or unexpected administrative commands.
Compensating Controls: Use a Web Application Firewall or network-level access controls to limit access to the Dynamics 365 interface to trusted internal networks only.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
System administrators must treat this as a high priority update. Applying the patch is the most effective way to eliminate the risk of remote code execution within the Dynamics 365 application.