CVE-2026-42898: Microsoft Dynamics 365 Remote Code Execution Vulnerability (nvd.nist.gov)
0xBASE INTEL BRIEF
- CVSS 9.9 – Critical
- Authenticated remote code execution
- All supported on-premises versions affected
"A critical code injection vulnerability (CVSS 9.9) in on-premises Microsoft Dynamics 365 allows authenticated attackers to execute arbitrary code over a network. Microsoft has released a security update. Immediate patching is strongly recommended due to the high CVSS score and potential for active exploitation."
no comments yet.