Executive brief
Microsoft Dynamics 365 on-premises is an enterprise business management system. A deserialization vulnerability allows authorized network users to execute arbitrary code on servers running this software, potentially compromising business data, operations, and customer information stored in the system.
Technical details
The vulnerability is a deserialization of untrusted data flaw in Microsoft Dynamics 365 on-premises. An authorized attacker can send specially crafted network traffic to trigger unsafe deserialization, leading to remote code execution. While authentication is required, the network-reachable attack vector means any authorized user with network access can exploit this. Patches are expected to be available through Microsoft's security updates.
Affected products
- Microsoft Dynamics 365 on-premises (specific versions not disclosed in advisory)
Timeline
- 2026-08-11: disclosed: CVE-2026-65815 published