Junglewise Threat Intelligence

CVE-2026-55944: Microsoft Dynamics NAV insecure deserialization remote code execution

CVE-2026-55944 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Vendors: Microsoft.

Executive brief

Microsoft Dynamics NAV, an enterprise resource planning (ERP) solution used for managing finances and operations, contains a critical security flaw. An attacker can exploit this vulnerability over the network without needing any login credentials or user interaction. Successful exploitation allows the attacker to take full control of the server, potentially leading to the theft of sensitive business data, disruption of operations, or the deployment of ransomware.

Technical details

A critical deserialization vulnerability (CWE-502) exists in Microsoft Dynamics NAV 2018. The flaw stems from the application improperly processing untrusted data, which can be manipulated to trigger the execution of arbitrary code. The attack vector is network-based and requires no prior authentication (PR:N) or user interaction (UI:N). An attacker who successfully exploits this vulnerability could achieve full system compromise with high impact on confidentiality, integrity, and availability. Microsoft has released updates to address this issue in version 11.0.50704.0 and later.

Affected products

  • Microsoft Dynamics NAV 2018 versions prior to 11.0.50704.0

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD

References