Junglewise Threat Intelligence

CVE-2026-77908: Microsoft Dynamics 365 code injection in code generation

CVE-2026-77908 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Microsoft Dynamics 365 is a cloud-based enterprise resource planning and customer relationship management platform used by organizations to manage business operations and customer interactions. A code injection vulnerability allows an authorized attacker to execute arbitrary code over the network, potentially compromising data integrity, enabling unauthorized access to business-critical systems, and disrupting operations.

Technical details

The vulnerability is a code injection flaw in the code generation mechanism of Microsoft Dynamics 365. An authorized attacker can exploit improper control of code generation to inject and execute arbitrary code over the network. This requires authentication and likely requires the attacker to have legitimate access to the system. Successful exploitation allows remote code execution within the Dynamics 365 environment, potentially leading to data exfiltration, lateral movement, or complete system compromise. A security update from Microsoft is available to address this vulnerability.

Affected products

  • Microsoft Dynamics 365

Timeline

  • 2026-09-08: disclosed

References

Related threats