CVE-2026-65815

8.8

Microsoft · Dynamics 365 (on-premises)

A deserialization of untrusted data flaw in Microsoft Dynamics 365 (on-premises) enables an authenticated attacker to execute arbitrary code over a network.

Executive summary

Microsoft Dynamics 365 (on-premises) is vulnerable to a high severity deserialization flaw that could lead to remote code execution.

Vulnerability

This vulnerability involves CWE-502, Deserialization of Untrusted Data, allowing an attacker with low-level authenticated access to achieve remote code execution.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting the high potential for system-wide impact. If exploited, an attacker could compromise sensitive business data stored within the Dynamics 365 environment or gain a foothold to further attack the internal network.

Remediation

Immediate Action: Update your on-premises Dynamics 365 installation to version 9.1.0047.0006 or later immediately.

Proactive Monitoring: Review system and application logs for anomalous deserialization errors or unexpected administrative commands.

Compensating Controls: Use a Web Application Firewall or network-level access controls to limit access to the Dynamics 365 interface to trusted internal networks only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

System administrators must treat this as a high priority update. Applying the patch is the most effective way to eliminate the risk of remote code execution within the Dynamics 365 application.

More Microsoft CVEs