« Back to list

Microsoft

Microsoft Dynamics 365: vulnerabilities and CVEs

Microsoft Dynamics 365 has 103 published vulnerabilities, 13 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs103
Last 12 months13
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-77908High (8.8)0.99%—Sep 8, 2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-65772High (8.8)1.7%—Sep 8, 2026
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
CVE-2026-66301Medium (6.5)1.00%—Aug 11, 2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVE-2026-65815High (8.8)1.7%—Aug 11, 2026
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-47647Critical (9.9)0.78%—Jun 18, 2026
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-40371High (8.8)0.78%—Jun 9, 2026
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
CVE-2026-42898Critical (9.9)0.99%—May 12, 2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42833Critical (9.1)0.93%—May 12, 2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-32210High (7.5)0.73%—Apr 23, 2026
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-33103Medium (5.5)0.35%—Apr 14, 2026
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
CVE-2025-62211High (8.7)0.60%—Nov 11, 2025
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62210High (8.7)0.60%—Nov 11, 2025
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62206Medium (6.5)0.92%—Nov 11, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-55238High (7.5)0.82%—Sep 4, 2025
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-53728Medium (6.5)1.2%—Aug 12, 2025
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-49745Medium (5.4)0.53%—Aug 12, 2025
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-49715High (7.5)0.83%—Jun 20, 2025
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
CVE-2024-43476Medium (5.4)0.89%—Sep 10, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38211High (8.2)1.00%—Aug 13, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38182Critical (9.8)0.88%—Jul 31, 2024
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVE-2024-30061High (7.3)1.4%—Jul 9, 2024
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-35263Medium (5.7)1.7%—Jun 11, 2024
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-21419Medium (5.4)1.1%—Mar 12, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21396High (7.6)1.2%—Feb 13, 2024
Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21395High (8.2)1.1%—Feb 13, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21394High (7.6)1.1%—Feb 13, 2024
Dynamics 365 Field Service Spoofing Vulnerability
CVE-2024-21393High (7.6)1.2%—Feb 13, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21389High (7.6)1.2%—Feb 13, 2024
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21328High (7.6)1.3%—Feb 13, 2024
Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21327High (7.6)1.3%—Feb 13, 2024
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter4
  2. T1210 Exploitation of Remote Services3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft