CVE-2026-55944: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Published Jul 14, 2026
·Updated
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected componentsFixes available
Microsoft Dynamics NAV 2018<11.0.50704.0
11.0.50704.0
Microsoft Dynamics NAV=2018
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverity
Data Sourced
via NVD·06:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-55944?
CVE-2026-55944 has a critical severity rating of 9.8.
2
How do I fix CVE-2026-55944?
To fix CVE-2026-55944, ensure that you apply the latest security updates provided by Microsoft for Dynamics NAV and Dynamics 365 Business Central.
3
What types of vulnerabilities are addressed in CVE-2026-55944?
CVE-2026-55944 addresses a remote code execution vulnerability caused by deserialization of untrusted data.
4
What versions of Microsoft software are affected by CVE-2026-55944?
CVE-2026-55944 affects Microsoft Dynamics NAV 2018 and Microsoft Dynamics 365 Business Central (On Premises).
5
Can CVE-2026-55944 be exploited remotely?
Yes, CVE-2026-55944 can be exploited remotely by an unauthorized attacker.