Microsoft
Microsoft Dynamics NAV: vulnerabilities and CVEs
Microsoft Dynamics NAV has 10 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55944 | Critical (9.8) | 1.5% | — | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. |
| CVE-2022-41127 | High (8.5) | 1.6% | — | Dec 13, 2022 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability |
| CVE-2022-41066 | Medium (4.4) | 1.2% | — | Nov 9, 2022 | Microsoft Dynamics Business Central Information Disclosure Vulnerability |
| CVE-2021-36946 | Medium (5.4) | 1.0% | — | Aug 12, 2021 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability |
| CVE-2021-1724 | Medium (4.8) | 1.3% | — | Feb 25, 2021 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability |
| CVE-2020-17133 | Medium (6.5) | 3.6% | — | Dec 10, 2020 | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability |
| CVE-2020-1022 | High (8) | 6.8% | — | Apr 15, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. |
| CVE-2020-1018 | High (7.5) | 6.3% | — | Apr 15, 2020 | An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who… |
| CVE-2020-0905 | High (8) | 11% | — | Mar 12, 2020 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. |
| CVE-2018-8651 | Medium (5.4) | 1.5% | — | Dec 12, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting… |