Microsoft Dynamics 365 vulnerabilities
92 known vulnerabilities affecting microsoft/dynamics_365.
Total CVEs
92
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH24MEDIUM62LOW2
Vulnerabilities
Page 1 of 5
CVE-2026-42898P2CRITICALCVSS 9.9≥ 9.1.1.914, < 9.1.45.112026-05-12
CVE-2026-42898 [CRITICAL] CWE-94 CVE-2026-42898: Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
nvd
CVE-2024-38182P2CRITICALCVSS 9.8v7.02024-07-31
CVE-2024-38182 [CRITICAL] CWE-1390 CVE-2024-38182: Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileg
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
nvd
CVE-2026-33821P2CRITICALCVSS 9.9v-2026-05-12
CVE-2026-33821 [CRITICAL] CWE-269 CVE-2026-33821: Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attac
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2018-8609P2HIGHCVSS 8.8≥ 8.0, < 8.2.3.00032018-11-14
CVE-2018-8609 [HIGH] CWE-116 CVE-2018-8609: A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365.
nvd
CVE-2020-16862P2HIGHCVSS 8.8v9.02020-09-11
CVE-2020-16862 [HIGH] CVE-2020-16862: <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the ser
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SQL service account.
An authenticated attacker could exploit this vulnerability by s
nvd
CVE-2020-16860P2HIGHCVSS 8.8v9.02020-09-11
CVE-2020-16860 [HIGH] CVE-2020-16860: <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the ser
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SQL service account.
An authenticated attacker could exploit this vulnerability by s
nvd
CVE-2026-42833P3CRITICALCVSS 9.1≥ 9.1, < 9.1.45.112026-05-12
CVE-2026-42833 [CRITICAL] CWE-250 CVE-2026-42833: Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) al
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
nvd
CVE-2021-34524P3HIGHCVSS 8.8v9.0v9.12021-08-12
CVE-2021-34524 [HIGH] CVE-2021-34524: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
nvd
CVE-2022-34700P3HIGHCVSS 8.8v9.0v9.12022-09-13
CVE-2022-34700 [HIGH] CWE-89 CVE-2022-34700: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
nvd
CVE-2026-40371P3HIGHCVSS 8.8≥ 9.1, < 9.1.45.112026-06-09
CVE-2026-40371 [HIGH] CWE-280 CVE-2026-40371: Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises)
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2022-23259P3HIGHCVSS 8.8v9.0v9.12022-04-15
CVE-2022-23259 [HIGH] CVE-2022-23259: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
nvd
CVE-2022-35805P3HIGHCVSS 8.8v9.0v9.12022-09-13
CVE-2022-35805 [HIGH] CVE-2022-35805: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
nvd
CVE-2021-42316P3HIGHCVSS 8.8v9.0v9.12021-11-10
CVE-2021-42316 [HIGH] CVE-2021-42316: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
nvd
CVE-2020-17152P3HIGHCVSS 8.8fixed in 10.0.112020-12-10
CVE-2020-17152 [HIGH] CVE-2020-17152: Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
nvd
CVE-2020-17158P3HIGHCVSS 8.8fixed in 10.0.112020-12-10
CVE-2020-17158 [HIGH] CVE-2020-17158: Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
nvd
CVE-2019-1229P3HIGHCVSS 8.8v9.02019-08-14
CVE-2019-1229 [HIGH] CVE-2019-1229: An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successful
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation.
To exploit this vulnerability, an attacker needs to have credentials for a user that has permission to author c
nvd
CVE-2022-21957P3HIGHCVSS 7.2v8.2v9.02022-02-09
CVE-2022-21957 [HIGH] CVE-2022-21957: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
nvd
CVE-2025-62211P3HIGHCVSS 8.7fixed in 8.8.139.3982025-11-11
CVE-2025-62211 [HIGH] CWE-79 CVE-2025-62211: Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2025-62210P3HIGHCVSS 8.7fixed in 8.8.139.3982025-11-11
CVE-2025-62210 [HIGH] CWE-79 CVE-2025-62210: Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-21778P3HIGHCVSS 8.0fixed in 4.2.0.512023-02-14
CVE-2023-21778 [HIGH] CWE-77 CVE-2023-21778: Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
nvd
1 / 5Next →