CVE-2026-77908: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
Other sources
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.1.0048.0004Patch KB5123731
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized to access the affected Microsoft Dynamics 365 Customer Engagement V9.1 deployment. The vulnerability is exploitable over a network and does not require user interaction.
What is the potential impact if exploitation succeeds?
Successful exploitation allows execution of code. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability.
Is Microsoft Dynamics 365 Customer Engagement V9.1 affected in cloud deployments?
The provided information identifies Microsoft Dynamics 365 Customer Engagement V9.1 and describes the issue as affecting Dynamics 365 On-Premises. It does not provide evidence that cloud deployments are affected.