0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Critical Vulnerabilities Patched in Microsoft Dynamics (advisories.ncsc.nl)

· 76d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • CVE-2026-42898 (CVSS 9.9) enables remote code execution in Dynamics 365 on-premises.
  • CVE-2026-40417 (CVSS 7.8) leads to privilege escalation in Business Central.
  • CVE-2026-40374 (CVSS 6.5) exposes sensitive data in Power Automate.

"The Dutch NCSC has issued an advisory about multiple vulnerabilities in Microsoft Dynamics components. The most critical, CVE-2026-42898 in Dynamics 365 (on-premises), has a CVSS score of 9.9 and allows an authenticated attacker to execute arbitrary code. Other flaws include privilege escalation in Business Central (CVE-2026-40417, CVSS 7.8), data access in Power Automate (CVE-2026-40374, CVSS 6.5), and privilege escalation in Customer Insights (CVE-2026-33821, CVSS 7.7). Microsoft has released patches; for CVE-2026-33821, no action is needed as it was already fixed. Users are urged to apply updates promptly."

Discussion Matrix

0 segments

no comments yet.