Microsoft
Microsoft Dynamics 365: vulnerabilidades y CVE
Microsoft Dynamics 365 tiene 103 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE103
Últimos 12 meses13
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65772 | Alta (8.8) | 1.7% | — | 8 sept 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. |
| CVE-2026-77908 | Alta (8.8) | 0.99% | — | 8 sept 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. |
| CVE-2026-66301 | Media (6.5) | 1.00% | — | 11 ago 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. |
| CVE-2026-65815 | Alta (8.8) | 1.7% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-47647 | Crítica (9.9) | 0.78% | — | 18 jun 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-40371 | Alta (8.8) | 0.78% | — | 9 jun 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42898 | Crítica (9.9) | 0.99% | — | 12 may 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-42833 | Crítica (9.1) | 0.93% | — | 12 may 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-32210 | Alta (7.5) | 0.73% | — | 23 abr 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-33103 | Media (5.5) | 0.35% | — | 14 abr 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. |
| CVE-2025-62211 | Alta (8.7) | 0.60% | — | 11 nov 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
| CVE-2025-62210 | Alta (8.7) | 0.60% | — | 11 nov 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
| CVE-2025-62206 | Media (6.5) | 0.92% | — | 11 nov 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-55238 | Alta (7.5) | 0.82% | — | 4 sept 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability |
| CVE-2025-53728 | Media (6.5) | 1.2% | — | 12 ago 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-49745 | Media (5.4) | 0.53% | — | 12 ago 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-49715 | Alta (7.5) | 0.83% | — | 20 jun 2025 | Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. |
| CVE-2024-43476 | Media (5.4) | 0.89% | — | 10 sept 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-38211 | Alta (8.2) | 1.00% | — | 13 ago 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-38182 | Crítica (9.8) | 0.88% | — | 31 jul 2024 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. |
| CVE-2024-30061 | Alta (7.3) | 1.4% | — | 9 jul 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2024-35263 | Media (5.7) | 1.7% | — | 11 jun 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2024-21419 | Media (5.4) | 1.1% | — | 12 mar 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21396 | Alta (7.6) | 1.2% | — | 13 feb 2024 | Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-21395 | Alta (8.2) | 1.1% | — | 13 feb 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21394 | Alta (7.6) | 1.1% | — | 13 feb 2024 | Dynamics 365 Field Service Spoofing Vulnerability |
| CVE-2024-21393 | Alta (7.6) | 1.2% | — | 13 feb 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21389 | Alta (7.6) | 1.2% | — | 13 feb 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21328 | Alta (7.6) | 1.3% | — | 13 feb 2024 | Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-21327 | Alta (7.6) | 1.3% | — | 13 feb 2024 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.