CVE-2026-65772: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Other sources
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.1.0046.0006
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected Microsoft Dynamics 365 on-premises deployment. The vulnerability is exploitable over a network and does not require user interaction.
What level of impact could successful exploitation have?
Successful exploitation allows the authorized attacker to execute code. The provided severity vector indicates high impact to confidentiality, integrity, and availability.
Are cloud-hosted Dynamics 365 deployments affected?
The available information identifies Microsoft Dynamics 365 on-premises only. It does not provide information about cloud-hosted deployments.