Microsoft
Microsoft Dynamics 365: vulnerabilities and CVEs
Microsoft Dynamics 365 has 103 published vulnerabilities, 13 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.
CVEs103
Last 12 months13
Critical4
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77908 | High (8.8) | 0.99% | — | Sep 8, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. |
| CVE-2026-65772 | High (8.8) | 1.7% | — | Sep 8, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. |
| CVE-2026-66301 | Medium (6.5) | 1.00% | — | Aug 11, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. |
| CVE-2026-65815 | High (8.8) | 1.7% | — | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-47647 | Critical (9.9) | 0.78% | — | Jun 18, 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-40371 | High (8.8) | 0.78% | — | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42898 | Critical (9.9) | 0.99% | — | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-42833 | Critical (9.1) | 0.93% | — | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. |
| CVE-2026-32210 | High (7.5) | 0.73% | — | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-33103 | Medium (5.5) | 0.35% | — | Apr 14, 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. |
| CVE-2025-62211 | High (8.7) | 0.60% | — | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
| CVE-2025-62210 | High (8.7) | 0.60% | — | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. |
| CVE-2025-62206 | Medium (6.5) | 0.92% | — | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-55238 | High (7.5) | 0.82% | — | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability |
| CVE-2025-53728 | Medium (6.5) | 1.2% | — | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-49745 | Medium (5.4) | 0.53% | — | Aug 12, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-49715 | High (7.5) | 0.83% | — | Jun 20, 2025 | Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. |
| CVE-2024-43476 | Medium (5.4) | 0.89% | — | Sep 10, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-38211 | High (8.2) | 1.00% | — | Aug 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-38182 | Critical (9.8) | 0.88% | — | Jul 31, 2024 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. |
| CVE-2024-30061 | High (7.3) | 1.4% | — | Jul 9, 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2024-35263 | Medium (5.7) | 1.7% | — | Jun 11, 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2024-21419 | Medium (5.4) | 1.1% | — | Mar 12, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21396 | High (7.6) | 1.2% | — | Feb 13, 2024 | Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-21395 | High (8.2) | 1.1% | — | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21394 | High (7.6) | 1.1% | — | Feb 13, 2024 | Dynamics 365 Field Service Spoofing Vulnerability |
| CVE-2024-21393 | High (7.6) | 1.2% | — | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21389 | High (7.6) | 1.2% | — | Feb 13, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21328 | High (7.6) | 1.3% | — | Feb 13, 2024 | Dynamics 365 Sales Spoofing Vulnerability |
| CVE-2024-21327 | High (7.6) | 1.3% | — | Feb 13, 2024 | Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.