Critical Vulnerabilities Patched in Microsoft Dynamics (advisories.ncsc.nl)
- CVE-2026-42898 (CVSS 9.9) enables remote code execution in Dynamics 365 on-premises.
- CVE-2026-40417 (CVSS 7.8) leads to privilege escalation in Business Central.
- CVE-2026-40374 (CVSS 6.5) exposes sensitive data in Power Automate.
"The Dutch NCSC has issued an advisory about multiple vulnerabilities in Microsoft Dynamics components. The most critical, CVE-2026-42898 in Dynamics 365 (on-premises), has a CVSS score of 9.9 and allows an authenticated attacker to execute arbitrary code. Other flaws include privilege escalation in Business Central (CVE-2026-40417, CVSS 7.8), data access in Power Automate (CVE-2026-40374, CVSS 6.5), and privilege escalation in Customer Insights (CVE-2026-33821, CVSS 7.7). Microsoft has released patches; for CVE-2026-33821, no action is needed as it was already fixed. Users are urged to apply updates promptly."
no comments yet.